Skip to main content
Security & privacy

Security you can read, not just trust.

Parlance is early, so instead of badges we haven’t earned, here is exactly how the product is built and what we’ve committed to in writing.

Read the privacy policy
How your data is protected

Built to keep your work separate and safe.

The protections below are how the product actually works today — not aspirations.

Tenant isolation by default

Row-level security guards every workspace table in the database, so one workspace can never read another’s data — enforced by Postgres itself, not just application code.

Encrypted in transit and at rest

Every request is served over TLS, and your data is encrypted at rest on our database and storage provider. Nothing travels or sits in the clear.

Strong authentication

Email and password, Google, GitHub, GitLab and Apple sign-in, two-factor authentication, SAML single sign-on and passkeys are all supported, with session tokens rotated automatically.

Secrets kept to a minimum

API keys are stored as one-way hashes and shown once; IP addresses are kept only as day-salted hashes and then pruned; invitations expire after seven days.

What we commit to

Promises we’ve put in writing.

Each of these is spelled out in our privacy policy and terms.

Your content is yours

We process the design and code you submit only to run your audits. We do not use your content to train models, or for anything unrelated to the audit you asked for.

Your data, your rights

Access, export, correct or delete your data from your account settings at any time. You can complain to the ICO, and — for readers in California — we do not sell or share your personal information.

Consent-first analytics

No analytics load until you allow them — nothing leaves the page before that. Our launch-updates list is double opt-in and stored in the European Union.

Named sub-processors

We list every third party that touches your data — our database, hosting, payments and email providers — in the privacy policy, and we will name any new one before it goes live.

Where we are — honestly.

Parlance has not been through SOC 2, ISO 27001 or an independent penetration test, and we will not display badges we haven’t earned. What we can show you is how the product is built — everything above — and the commitments we’ve put in writing. That is the honest picture today.

Report a concern

Found a security or privacy issue? Email privacy@parlancelabs.net and we’ll get back to you. For anything else, our support page has the fastest route.