Security & trust
Enterprise and mid-market buyers evaluate vendors quickly. This page collects the basics procurement and technical reviewers typically ask for when considering Get Stuff Done.
Security overview
- Client data is stored in Firebase (Google Cloud) with tenant isolation via Firestore security rules.
- Payment card data is not processed on our application servers; use your chosen processor’s hosted fields.
- API keys are shown once at creation; only hashes are stored server-side.
- Outbound webhooks require HTTPS endpoints in production.
Policies
Operational baseline resource
For teams building their own program, start with our free security baseline checklist and companion article. Not legal or certification advice.
Questionnaires & DPAs
Email connect@alphesda.com with your company name, data types involved, and deadline. We respond with available documentation or a clear timeline for custom questionnaires.