Security Statement
The commitments behind the security overview, written as contract-adjacent detail rather than marketing copy.
1. Our commitments
Encrypted connections, workspace-scoped access control, role-based permissions and audit logging of privileged actions.
Managed secret storage: credentials and provider keys are never stored in application code or exposed to browsers.
Server-side enforcement of plan limits, extraction limits and communication controls, so protections cannot be bypassed from the client.
2. Payments
Card details are handled by the payment provider. Phloem stores only the amount, currency, status and provider reference of a transaction.
Payment callbacks are signature-verified and replay-protected before any account state changes.
3. Your responsibilities
Keep credentials confidential, invite colleagues as workspace members instead of sharing logins, and review member roles regularly.
Rotate API keys you no longer use, and report suspected unauthorised access immediately.
4. What this statement is not
This statement describes commitments and practices. It is not a certification, an audit report or a guarantee that no incident can occur.
Where a certification or a customer-specific security assessment is required, ask through the support form so it can be handled properly.
5. Reporting a vulnerability
Report suspected vulnerabilities through the support form using the Security topic. Include steps to reproduce and the affected URL.
Do not test against other customers' data, do not run denial-of-service tests, and do not access accounts that are not yours.
Legal, privacy and security contact runs through the Phloem support form and privacy centre — we do not publish individual inboxes.

