P Eduba
Security & trust

Multi-tenant SaaS that any security team can sign off on.

The controls below are surfaced in language a security reviewer can use to fill in their questionnaire.

How we isolate data
  • Database-per-tenant (no shared tables).
  • S3-compatible storage with per-tenant buckets and presigned URLs.
  • Optional BYO database and BYO storage.
  • Cross-tenant analytics only via the master plane.
Authentication & access
  • Lucia sessions + JOSE; OAuth PKCE for native apps.
  • MFA (TOTP, passkeys); SSO (OIDC/SAML) on Enterprise.
  • Per-row policy with segregation of duties for finance.
Audit & immutability
  • Append-only event store; append-only stock & GL ledgers.
  • Every policy decision audited (policy.evaluated).
  • Tenant-exportable security event log.
Encryption
  • TLS everywhere (auto-issued via Caddy); HSTS preload-eligible.
  • AES-256-GCM at rest for secrets; tenant-managed keys on Enterprise.
Compliance & residency
  • Data residency via region pinning (managed) or BYO (any region).
  • Custom retention windows on append-only stores; legal hold supported.
  • GDPR-style export and erasure workflows.
  • SOC 2 Type II in progress (target Q3 2026).
Vulnerability & supply chain
  • Dependency scanning + SAST/DAST in CI.
  • Signed workflow packs and blocks (signatures verified at import).
  • Coordinated disclosure: security@eduba.app · security.txt
Status & uptime
99.97% over the last 90 days · Live status
Responsible disclosure
Response window
Acknowledged within 24h · status update within 5 business days.
In scope
  • · The marketing site, the tenant app, and the platform API.
  • · Workflow runtime, block SDK, connector framework.
  • · Self-hosted runtime (Docker / Helm), license validation.

Need a deeper review? We'll walk through it on a call.