Security
Because there aren't any. untactit authenticates through your existing identity provider, which means there is no password database here to breach.
Sign-in goes through Google, Microsoft, or your SAML provider. We never see, hold, or transmit a password — there is no credential table to steal.
Every record carries its organization. Queries are scoped at the data layer, not filtered in the interface — a missing filter fails closed, not open.
Who changed what, when, and from where. Entries are written once and never edited — including by us.
Permission is decided by the server on every request. The interface reflects that decision — it never makes its own.
Identity providers
TLS 1.2 or higher on every connection, including internal service traffic.
Encrypted storage volumes with managed keys. Backups inherit the same encryption.
Vendor credentials are encrypted at the application layer with a separate key, so a database dump alone does not expose them.
Disk-level encryption stops a stolen drive. It does not stop a leaked backup or an over-broad query, so we encrypt sensitive fields separately.
Security pages usually list certifications. Here's where we actually are.
Security questions, disclosure reports, or a DPA request — get in touch. We answer security mail before we answer sales mail.
Connect one workspace and see every skill, rule, and memory your team has in play — in about ten minutes.
No credit card. Works with what you already run.