Security
How we protect your data in Nuje.
Launch posture
Nuje is currently an invite-only product run by our team. Public self-serve signup, billing, and formal SOC 2 certification are not yet part of this release.
Access controls
- Authentication is handled by WorkOS AuthKit.
- Workspace creation and invite acceptance are restricted to an approved email allowlist.
- Development authentication and test hooks are disabled in production.
- Private channels and DMs require membership for search, media reads, thread access, live updates, and any write or control action.
- Administrative access to private channel or DM content is kept separate from normal in-app routes.
Data protection
- Postgres is the system of record, hosted on Neon with 7-day point-in-time recovery (PITR).
- Uploaded files are stored in a private object-storage bucket and served only through authenticated app routes.
- Service credentials are stored as platform secrets and redacted from logs.
- Errors are reported to Sentry; operational traces and metrics are exported to Grafana Cloud.
Retention
Deleted media is soft-deleted first and then purged. Incomplete uploads are aborted after one day, and our runbooks document a 30-day media-deletion and orphaned-object retention policy.
Known gaps
- Formal SOC 2 certification, immutable audit-log export, and automated compliance evidence are still in progress.
- Application logs are redacted at the source; we review them before treating them as shareable.
- On-call paging, expanded abuse tooling, and multi-region disaster recovery are still in progress.
- A published security contact will be in place before wider public availability.
See also our subprocessors.