Skip to content
Demo content — this page shows example security and trust information for the Public Surface template. Badges, compliance status and sub-processors below are fictional. Replace them with your own before publishing.
SECURITY & TRUST
Security you can verify
How Public Surface protects customer data, and what to expect when your security team reviews us. This page is example content for the template — replace every claim with your own posture before you publish.
PRINCIPLES
How we think about security
Encrypted by default
TLS 1.3 in transit and AES-256 at rest, on every plan, with no configuration required.
Least-privilege access
Role-based permissions and scoped API keys throughout the product, not just at the account level.
Independently reviewed
Built to withstand the security questionnaires and audits that come with selling upmarket.
Transparent by design
Status, incidents and security-relevant changes are published, not handled behind closed doors.
ENCRYPTION & DATA PROTECTION
Data protection
IN TRANSIT
TLS 1.3 for all client and internal traffic, with modern cipher suites enforced everywhere.
AT REST
AES-256 encryption for databases, object storage and backups.
KEY MANAGEMENT
Managed encryption keys with periodic rotation; customer-managed keys available on Enterprise (example).
DATA RETENTION
Configurable retention windows, with deletion on request completed within 30 days (example).
AUTHENTICATION & ACCESS
Authentication and access controls
SINGLE SIGN-ON
SAML 2.0 and OIDC, enforceable per workspace so every login goes through your identity provider.
DIRECTORY SYNC
SCIM provisioning for Okta, Entra ID and Google Workspace keeps membership in sync automatically.
ROLE-BASED ACCESS
Owner, Admin, Member and Read-only roles are available on every plan, not gated to Enterprise.
MULTI-FACTOR AUTH
Required for all workspace owners and admins; optional and enforceable for everyone else.
AUDIT LOGS
Exportable log of authentication events and permission changes (example).
INFRASTRUCTURE & AVAILABILITY
Infrastructure and availability
HOSTING
Multi-region cloud infrastructure with automated failover between availability zones (example).
UPTIME
99.95% uptime target, with status and incidents published live on our status page (example).
BACKUPS
Automated daily backups with point-in-time recovery, retained on a rolling window (example).
DATA RESIDENCY
Choose US or EU storage at the project level; data does not leave the selected region.
VULNERABILITY REPORTING
Responsible disclosure
If you believe you’ve found a security vulnerability in Public Surface, we want to hear about it. Report it privately and we’ll work with you to understand and resolve it before any public disclosure.
01 — REPORT
Send us the details
Email a clear description, steps to reproduce, and any proof-of-concept to our security address.
02 — ACKNOWLEDGE
We confirm receipt
Expect an acknowledgement within 2 business days, with an initial assessment to follow (example).
03 — RESOLVE
We fix and disclose
We patch confirmed issues and coordinate disclosure timing with you before going public.
security@publicsurface.dev
COMPLIANCE
Compliance posture (example)
The table below is an example compliance posture for this template. Replace it with your organization’s real certifications, audit dates and evidence links.
SOC 2 Type II
Readiness
Audit engagement underway — target completion Q4 2026 (example).
GDPR
Compliant
Data processing addendum available on request (example).
CCPA
Compliant
California privacy rights supported for all customers (example).
ISO 27001
Planned
Certification planned for 2027 as the company scales (example).
SUB-PROCESSORS
Sub-processors (example)
Third parties we use to help operate Public Surface. The provider names below are fictional examples for this template — replace this table with your own vendor list.
LEGAL
Privacy and legal resources
Privacy Policy
Connect your legal page
Terms of Service
Connect your legal page
Data Processing Agreement (DPA)
Connect your legal page
Sub-processor list
CONTACT
Talk to security
Security questionnaires, procurement reviews, or a vulnerability report — reach the team directly and we’ll get back to you.