Security at Fajita is about reducing risk through clear, enforced boundaries, not absolute promises.
What Fajita does
- Encrypts data in transit.
- Encrypts supported secrets at rest.
- Isolates each organization's data through server-side authorization and database row-level security.
- Enforces role-based access on the server.
- Restricts what monitors and webhooks can reach. See Monitoring destinations.
- Signs generic webhooks so you can verify authenticity.
What Fajita does not claim
Fajita does not claim certifications it has not earned. Any compliance status is stated only when it is real and documented.
Report a vulnerability through Responsible disclosure.