Security at UnDebify

Your cap table is not a document. It is evidence.

UnDebify holds the records a young company cannot afford to lose or to have quietly rewritten: who owns what, who decided what, and when. This page sets out how that is protected, who can reach it, and what we do not claim.

Version
1.1
Updated
September 2026
Status
Beta
  • 01

    One provider. Switzerland.

    Compute, database, files and email all run in a Swiss region of Infomaniak Public Cloud, in datacentres they own and operate, certified to ISO 27001 and ISO 9001.

  • 02

    Nothing else is loaded.

    No third-party analytics, no tracking pixels, no error monitoring service, no content delivery network, no AI provider. We record a small number of usage events on our own servers and send them nowhere. No cookie banner is needed, because no optional cookies are set.

  • 03

    No passwords exist.

    You sign in with a one-time link or a passkey on your device. There is no password to leak, reuse or phish, and only one session per person is live at a time.

The control that matters most

One compromised account cannot rewrite your cap table.

Most tools protect the login and stop there. If someone gets into a founder's account, they get everything. UnDebify treats ownership changes as decisions rather than edits, so they need agreement from the people they affect.

Revising an existing ownership record requires unanimous approval from every confirmed founder and investor, plus the explicit consent of whoever holds the entry being changed. Issuing new shares requires a board or founder majority, counted one vote per person rather than by shareholding, so even a majority holder cannot issue shares alone. Removing a founder requires the unanimous agreement of the others and cannot happen while they still hold equity.

These are not settings that can be switched off during an attack. They are how the actions work.

04How your data is protected

Separation, access, and a record of both

Four things carry most of the weight. Everything else is ordinary hygiene we also do.

  • One company, one boundary

    Every company's data is separated inside the database itself, not only in application code. A query scoped to another company returns nothing, by design rather than by convention, and an automated check blocks any release that would weaken it.

  • Sign-in that cannot be reused

    One-time links and passkeys, with rate limiting on sign-in requests. Signing in on a new device ends the previous session immediately, so there are no forgotten sessions on old machines.

  • Documents stay private

    Uploads live in private storage with no public links, encrypted at rest by our provider. Every download is checked against your permissions at the moment of the request, not at the moment the link was made.

  • A record you can read yourself

    Governance and security events are written to an append-only trail the database itself will not let anyone edit or delete. Your team can see it inside the product, in the Activity Log.

05What happens to your data

Kept, backed up, and yours to take

  • Backed up daily. The database and your uploaded files are copied every day to Swiss backup storage.

  • Yours to export. You can generate a complete export of your company at any time: structured data, a readable report, and checksums so a recipient can confirm nothing was altered.

  • No lock-in. That export exists so you can leave, share with an investor, or settle a question without asking us for anything.

  • Never sold. Not to advertisers, brokers, investors, accelerators or partners. A partner code affects your price, nothing else.

  • Never used to train models. No workspace content is sent to any external AI service. Not ownership, not financials, not co-founder data.

  • Support access is limited and logged. A small number of technical staff can reach workspace data when needed to run the service or answer a support request. Administrative changes are recorded.

  • Nobody pulls the plug alone. Cancelling an account needs every founder to approve, and it makes the workspace inactive rather than destroying anything. Permanent erasure is a separate request you send us, and it needs one person here to raise it and a second to approve. No single account, on either side, can end a company.

  • Built on GitHub. Our deployment pipeline builds and releases the software. It does not process your workspace content.

  • Your email is your account. With no password, whoever controls your inbox can request a sign-in link. Add a passkey: it is also the only way back in if you ever lose access to that inbox.

06Stated plainly

What we do not claim

A trust page that only lists strengths is marketing. Here is the other half.

  • No certification of our own. We hold no SOC 2 or ISO 27001. Our infrastructure provider does, and commits contractually to annual intrusion testing of that layer, but that is their certification, not ours. We will say so the day it changes.

  • No independent penetration test of our application yet. Security reviews happen during development. An external test is on the list, and it is not done.

  • Encryption at rest covers files and backups. Uploaded files and backup copies are encrypted at rest. Full database-level encryption at rest is on our roadmap, not in place today.

  • We are a company in formation. Until UnDebify is entered in the Swiss commercial register, it operates as a partnership between its founders.

  • UnDebify is not legal, tax, or financial advice. It organises your records and keeps them honest. It cannot make a bad agreement good, and it cannot prevent bad faith by someone with legitimate access.

We would rather be checkable than impressive. If something is not listed on this page, assume it is not in place, and ask us.

07Questions, or something you want to break

We answer technical questions properly.

Security questions and responsible disclosure: . We answer diligence questionnaires directly and will walk through the architecture with your team. If you find something, tell us and we will credit you.

Swiss hosted

Swiss built

undebify.com