Trust & control

Your data is yours.

No lock-in isn't a footnote — it's a selling point. SEDER ONE is built so leaving is a button, not a battle, and so every action is accountable from the ground up.

Accountable by design

Control, isolation, and a clean audit trail.

Deployment-boundary isolation

Each customer runs in its own deployment and database — isolation at the strongest boundary, not shared rows in a shared table.

Secrets encrypted at rest

Integration credentials — API keys and OAuth tokens — are encrypted at rest with AES-256-GCM before they're stored; only non-secret metadata is kept in the clear.

Roles & permissions

Role-based access through positions with per-module permissions — each person sees and does only what their role allows, across every module you've turned on. Entitlements are read from the live record on every request, so a permission change takes effect immediately, not at next login.

Append-only audit log

Actions across the platform are written to an append-only log of who did what and when — accountable by design, and a clean story for an auditor.

Secure sign-in

Passwords are hashed with bcrypt and never returned; password-reset tokens are single-use and short-lived.

Export & GDPR erasure

One click produces a complete, machine-readable copy of everything — and GDPR data export and erasure are built in. Your data is yours to take, or to remove.

Sessions you can revoke

Sessions last 24 hours and slide with activity, so an idle one ends within a day. Sign-out, a password reset or deactivation revokes every session at once — re-checked on the next request, not left to expire.

Uploads can't run in the browser

Uploaded files are always served as downloads, never rendered in the browser, with content-type sniffing off. Only inert formats — PDFs and images — are handed back with their own content type; anything else is returned as generic binary. So a document can't execute in someone else's session.

Hardened by default

A per-request Content-Security-Policy nonce means scripts run only from our own origin; framing is denied outright (X-Frame-Options: DENY), and HSTS keeps every connection encrypted.

No lock-in

Most incumbents make leaving painful. We make it a button.

Your business's data belongs to your business. A one-click export gives you a complete, machine-readable copy any time, and SEDER ONE can be self-hosted — so you're never trapped in someone else's cloud. That's the confidence of a platform that has to earn its keep every month.

Integrations are bring-your-own, too: you connect your own accounts — payments, accounting, email and more — and we never broker a shared one.

See the integrations →

Found a security issue? See our vulnerability disclosure policy. Formal certifications and compliance statements will be published here as they're completed.