Skip to content
EightySixOS

Security

Security is a feature. Not a chore.

How I am building EightySixOS to keep your data yours, explained plainly.

Data ownership

The agency owns its data. The client owns theirs. EightySixOS just keeps it safe.

The foundations

Built to keep you in control.

Isolation by default

EightySixOS is multi-tenant, and every row of data is scoped to your agency. The database denies access by default and grants it only through your team's memberships, checked on every request. One agency can never see another's work.

Encryption

Data is encrypted in transit and at rest. The tokens that connect your providers are stored encrypted, never in plain text.

Secure authentication

Email and password, invitations and sessions, handled by a proven authentication layer. Access is always derived from who you are on the team, never assumed from the browser.

Your keys, your connections

Where it matters, the philosophy is bring-your-own-keys. Your provider connections belong to your agency, not to us.

Evidence you own

The proof you capture, and the files behind it, belong to your agency. Nothing is held hostage.

No lock-in

Export is a right, not a favour. You can take your data with you whenever you want.

In the open

EightySixOS is in active development. This is how I am building it, honestly. I am not formally certified yet, and I will not pretend to be. When I pursue compliance, I will say so, and show my work.

Your work. Your data. Your control.