Security

Enforced in the database, not promised in a contract

A policy document describes intentions. These are constraints — the kind that make the wrong thing impossible rather than discouraged. Where a guarantee is only a policy, this page says so.

Isolation

Your records cannot be reached from another account

In one line: the evidence record is append-only at the database level, so nobody can rewrite history — including us. The gaps are named on this page rather than left for your review to find.

The record

What is written cannot be quietly rewritten

Access

Sessions, passwords and what happens when something goes wrong

Recent, and verifiable

Shipped this quarter, checkable today

Reviews and questionnaires

Ask us anything your review needs

We answer security questionnaires directly. Send yours and you will get a complete, specific response — including where a control is structural, where it is procedural, and where it is neither yet. We would rather have that conversation with your reviewer than pre-answer it for the whole internet.

Architecture detail on request. How tenancy is enforced, how the append-only guarantees are implemented, how sessions are revoked and what the retention boundaries are — available under NDA to anyone evaluating seriously.

Responsible disclosure

Found something? Tell us.

Security reports are read before anything else in the inbox and answered by someone who can fix it, not by a triage queue. Tell us what you found and how to reproduce it. We will confirm we have it, tell you what we are doing, and say when it is fixed.

We will not threaten you, and we will not argue about scope with somebody who took the trouble to tell us.

Report a vulnerability or write to hello@selahai.ai
Questions

Send the security questionnaire

It will come back with straight answers, including the ones that say no.

Contact