AnchorMark

Security

AnchorMark is built tenant-first. Every domain table carries an organization_id column and every API route resolves the caller's membership before reading or writing data. A cross-tenant smoke test runs in CI to make sure callers cannot read another organization's rows even if they guess the id.

Posture

  • TLS 1.2+ in transit; AES-256 at rest with KMS-managed keys.
  • Sessions are server-side, hashed, and cookie-bound.
  • OIDC login (Replit Auth today; Clerk swap in Phase 10).
  • SSO & SCIM via WorkOS on the Enterprise tier.
  • An immutable audit log records every privileged write.
  • Secrets live in Replit's secret store — never in source.
  • Field-level redaction for sensitive inputs marked by your SDK config.

Compliance

Our DPA and sub-processor list are published on this site (DPA summary, sub-processors). A BAA is available on the Enterprise plan for customers handling PHI.

Disclosure

For our security disclosure process, see the contact page.