Security
Recognition is
personal data.
A card says something true about a named person, written by another named person. That deserves the same care as a payroll record, even though it reads like a note.
Who can see what
The visibility of a card is set once, by the sender, at the moment of sending. Nothing later reclassifies it upward.
| Visibility | Sender | Recipient | Signers | Department | Company |
|---|---|---|---|---|---|
| Private (default) | Yes | Yes | Yes | — | — |
| Team visible | Yes | Yes | Yes | Yes | — |
| Company visible | Yes | Yes | Yes | Yes | Yes |
Workspace owners and HR admins can see aggregate participation, never the contents of a private card they were not part of. That distinction is the whole design.
Controls
Encryption
TLS 1.3 in transit and AES-256 at rest, on managed infrastructure in the EU or US depending on which region your workspace is created in.
SSO and SCIM
SAML single sign-on and directory provisioning on Enterprise.
Audit log
Every permission and policy change, with actor and timestamp.
Retention
You set how long a card lives. The default is: as long as the workspace does.
Export and deletion
Full workspace export in CSV and JSON on demand. A departing employee takes a copy of every card they received. Deletion requests are honoured within 30 days.
Compliance certifications and the current subprocessor list live in the trust centre, which is not built yet. Ask us directly in the meantime.