Trust
Trust center
We publish the policies and controls currently in operation. Planned controls and certifications are identified explicitly.
In operation
Controls running today
A summary of the practices described on the Security page.
Application security
- HTTPS in production for application traffic
- Secure session cookies and email verification in production
- CSRF and origin protections on sensitive auth flows
- SSRF protections on outbound monitoring checks
Infrastructure
- Managed Postgres (Neon) with TLS
- Distributed rate limiting via Redis when configured
- Environment validation that fails closed in production
Access control
- Workspace membership and role checks on server actions
- Feature entitlements enforced server-side
- Secrets kept in environment configuration, never in client code
Monitoring and response
- Structured logging with secret redaction
- Health endpoints for liveness and readiness
- Operational alerts for critical platform failures
Not yet available
What we don't claim
Mydle is an early-stage service. These are not in place today, and we say so rather than imply otherwise.
- Not availableFormal certifications or a SOC report
- Not availablePenetration-test reports
- Not availableEvery enterprise control — SSO is Enterprise-only and validated with your IdP
Documents
Policies and legal
Security
Found a security issue?
Email security@mydle.app. Please don't disclose publicly until we have had a reasonable chance to investigate.