Security / Current controls
Trust starts with accurate claims.
Citarra protects customer workspaces with practical technical controls and clear disclosure about certifications and capabilities that are still in progress.
Control map
What protects the workspace today.
These are current safeguards, described without stretching them into certifications or capabilities Citarra does not yet hold.
Tenant separation
Workspace isolation is enforced at the database layer to reduce cross-customer access risk.
Data protection
Data is encrypted in transit and at rest through Citarra’s infrastructure controls.
Activity history
Important product activity is written to an append-only audit trail.
Workspace membership
Customer data is limited to authorized members of the applicable workspace.
Paid API tiers
Customer submissions are not intentionally used to train Citarra models.
Paddle checkout
Paddle processes subscriptions as Citarra’s Merchant of Record.
Certification status
What we do not claim.
Citarra is not currently SOC 2 certified.
A formal audit is planned. Citarra will not display a certification or compliance claim until the applicable assessment has been completed.
Enterprise controls are documented when available.
SSO, granular administrative roles, and advanced retention controls are not presented as current capabilities until released.
Responsible disclosure
Found a security issue?
Email hello@citarra.com with the affected area and safe reproduction details. Do not access customer data or disrupt the service while investigating.
Customer requests
Privacy, exports, and deletion.
The Privacy Policy explains the data categories Citarra processes and the services involved.
For security, privacy, export, or deletion questions, contact hello@citarra.com.