Skip to content
grewray

Isolation first. Then everything else.

Many businesses share grewray; none of them can ever see another's data. That was the first thing built, before any feature, and it is enforced four times over.

1. Query scope2. Write check3. Access rule4. DatabaseYour data

Four layers, each enough on its own.

They are independent on purpose. For your data to reach another business, all four would have to fail at once, and each one is tested on every change we make.

  1. 1

    Every query is scoped

    Each read the application makes is filtered to your business before it runs.

    Stops: A developer forgetting to filter by business.

  2. 2

    Every write is checked

    Records are stamped with your business when saved, and a write for any other business is refused.

    Stops: Data saved under the wrong business, or none.

  3. 3

    Every request is authorized

    Before anything is returned, a rule confirms the record belongs to the business you are signed in to.

    Stops: A record reached by a path that skipped the first two layers.

  4. 4

    The database enforces it too

    Row-level security in the database itself refuses rows from other businesses, whatever the application asks.

    Stops: Anything that gets past the application entirely.

Accounts that stay yours.

  • Two-factor sign-in, required where it matters

    Anyone who can change your business's settings, billing or team must use an authenticator app. It is not optional for owners and admins.

  • Signing out means signed out

    Ending a session, resetting a password or changing two-factor takes effect on the very next request, on every device.

  • Stolen tokens stop working

    Sign-in tokens rotate on every use. If an old one is replayed, the whole chain is revoked and the person has to sign in again.

  • No data in error messages

    Errors never echo identifiers, table names or query text back to a browser, and sensitive fields never reach a log.

The numbers we hold ourselves to.

Your data is encrypted in transit and at rest, backed up continuously, and restorable to any point in the last month.

Monthly availability target
99.9%
For the app and the API. Planned maintenance is announced 72 hours ahead.
Recovery point
5 min
Point-in-time backups mean a restore loses no more than a few minutes of work.
Recovery time
4 h
The longest a full restore is allowed to take.
Backup retention
30 days
Restores are tested every quarter. An untested backup is not a backup.
Incident acknowledgement
15 min
Any suspected exposure between businesses is treated as our highest severity, always.

Your data is yours.

Export everything, whenever you like, in open formats, at no charge. Close your account and your business's data is deleted, with notice at every step. We never sell it.

Found a vulnerability?

Tell us privately and we will work with you on it. We acknowledge every report and keep you updated while we fix it.

Report to hello@grewray.com

Give the paperwork to grewray.

Start a free trial today. If you have data to bring, we move it in for you.