Back to milestra.app

Trust

Security

Last updated September 2026

Milestra is built to hold your organization's performance data — goals, reviews, evidence — to a standard your security team can sign off on. Here's how.

Encryption everywhere

All traffic is served over TLS. Data at rest — including evidence files — is encrypted with AES-256 by our database and storage provider.

Per-organization isolation

Every query runs through PostgreSQL row-level security policies scoped to your organization. One workspace can never read another's rows, even via the API.

Least-privilege access

Access to production systems is limited to a small number of named staff, each using multi-factor authentication on every provider account. We don't access customer content except to provide support you've requested.

Authentication controls

Password-based sign-in enforces minimum strength and is rate-limited; sessions expire and are refreshed server-side. Google sign-in is supported; SAML single sign-on is on the roadmap.

Backups and recovery

The database is backed up daily by our hosting provider (Supabase). Deletes of goals and related records are restricted by role, and the audit log cannot be edited or erased by workspace members.

Incident response

Errors are captured and alerted automatically, and live service health is published on our status page. Customers are notified of confirmed personal-data incidents within 72 hours per our DPA.

Report a vulnerability

Found something? Email security@milestra.app with details and steps to reproduce. We acknowledge reports within one business day and won't take action against good- faith research.

Compliance documentation

Our DPA, subprocessor list, and privacy policy are published for review. We are happy to complete security questionnaires for evaluating customers. An independent penetration test and SOC 2 audit are planned but not yet complete — we will publish them here when they are.