Trust Portal
Security overview
All EmDash traffic and customer data in transit is encrypted over TLS via Cloudflare's edge network. Application data at rest is stored in dedicated, credential-scoped Postgres databases with row-level security, and background jobs authenticate with least-privilege, per-service database roles rather than a single shared credential.
Data security
How customer data is protected in transit, at rest, and over its lifecycle.
Encryption in transit
All traffic between browsers, EmDash's Cloudflare Workers, and backend services including database connections are encrypted with TLS.
Encryption at rest
Application and platform Postgres databases, and object storage (Cloudflare R2), are encrypted at rest by their respective infrastructure providers.
Backups
Application and platform databases run on PlanetScale-managed Postgres, which handles automated backups of hosted databases as part of its managed service.
Data retention & deletion
Stored objects are automatically deleted within 90 days. Objects can be deleted earlier on request.
Subprocessors
Third-party services that store or process customer data on EmDash's behalf, and where each one operates.
| Subprocessor | Purpose | Data location |
|---|---|---|
| Cloudflare, Inc. |
| Global edge network |
| PlanetScale, Inc. |
| Sydney, Australia |
Data locations
A quick reference for where EmDash-controlled customer data lives.
Application & platform databases
Sydney, Australia (PlanetScale Postgres)
Compute, static assets & queues
Cloudflare's global edge network, with no single fixed region
Microsoft 365 data
Remains in each customer's own Microsoft 365 tenant. EmDash accesses it via the Microsoft Graph API under the customer's own region and consent scope, and does not copy or relocate it outside that tenant.
Network
How requests move between EmDash, Cloudflare's edge network, and our database origin.