Security at Ambiguous.
How Ambiguous protects your workspace today, what we don't have yet, and how to report issues.

How we protect your data
Three architectural decisions that make data breaches structurally difficult, not just operationally unlikely.
Workspace isolation
Every workspace is scoped at the ORM level. Cross-tenant data access is structurally impossible. Not just policy-prohibited; architecturally prevented.
Complete audit trail
Every action by every user and every AI coworker is logged with actor, timestamp, resource, and outcome. Immutable, queryable, exportable.
Encryption everywhere
TLS 1.3 in transit, AES-256 at rest. JWTs expire in 15 minutes, refresh tokens rotate on every use. No plaintext secrets, no downgrades.
What we do today
Production security posture as of May 2026.
TLS 1.3 everywhere
All traffic encrypted in transit. No exceptions, no downgrades.
Encryption at rest
All data encrypted at rest using AES-256. Database, file storage, backups.
Workspace isolation
Every workspace is scoped at the ORM level. Cross-tenant data access is structurally impossible.
Password hashing
bcryptjs with cost factor 12. Passwords are never stored in plaintext.
Short-lived tokens
JWT access tokens expire in 15 minutes. Refresh tokens rotate on every use.
HTTPS-only
HSTS enforced. No HTTP fallback. Secure cookies with SameSite=Strict.
Rate limiting
Per-IP and per-account rate limiting on all API endpoints. Brute-force protection on auth.
Access reviews
Regular access reviews for all team members. Least-privilege by default. MFA required for all internal access.
Incident response
Documented incident response runbook. Notification within 72 hours of confirmed breach per GDPR.
What we don't have yet
Honest about our current scope. These are real gaps we intend to close.
SOC 2 Type II
Audit engagement started Q2 2026
ISO 27001
Planned after SOC 2 completion
HIPAA BAA
Not available today
FedRAMP
No current plans
Penetration testing report
Annual third-party pentest scheduled Q3 2026
Responsible disclosure
Found a vulnerability? We want to hear about it.
Direct email. No contact forms, no ticket queues. You reach the security team.
Encrypted communication
For sensitive disclosures, request our PGP public key via the email above. We will reply with the key and fingerprint for verification.
Disclosure window
90 days from report to public disclosure. We aim to acknowledge within 48 hours and provide a fix timeline within 7 days.
Trust artifacts
Real-time status and external references.
Frequently asked questions
We follow a documented incident response runbook. Affected customers are notified within 72 hours per GDPR requirements. Fix timeline communicated within 7 days.
Contact the security team
Questions not answered here? Email us directly. We respond to every inquiry.