Skip to main content
Trust center

Trust and security

Understand Phasoric security boundaries, encryption scope, retention, subprocessors, disclosure, and incident practices.

Trust starts with clear boundaries and evidence—not certification theater.

Encryption scope

When optional vault encryption is enabled, Phasoric protects Markdown before provider writes and refuses to write plaintext while locked. Attachment bytes, filenames, provider metadata, and every third-party service have separate boundaries; they are not covered merely because Markdown encryption is on.

Hosted boundaries

Hosted identity, membership, billing, credentials, and authorization use a control plane. Hosted knowledge and persisted collaboration state use a separate knowledge plane. Private files are mediated through authenticated or capability-bound routes.

Retention, export, and deletion

Markdown remains exportable. Account deletion revokes sessions and public capabilities before retryable data erasure. Signing, Trash, captures, telemetry, and provider artifacts have explicit retention paths rather than one ambiguous delete state.

Infrastructure and disclosure

Hosting, managed database, transactional email, private object storage, security, and opted-in intelligence services may process the minimum data required for their role. Stripe processes billing. Exact infrastructure identities are available through confidential customer procurement or DPA review when required. Report a vulnerability to security@phasoric.com. See the security policy and service status.

Capture evidence. Make the decision. Approve the action.

Phasoric keeps that chain connected to portable knowledge and visible trust boundaries.

Create a workspace