Local-first storage
Boards are written to your own disk and read from there. The primary copy is yours. The application works fully offline, and an outage on our side does not take your work away.
Launch 20% off every paid plan for the first year.
See the plansTrust centre
Every control on this page is in the product today, and you can check each one by opening it. The strongest of them is also the simplest. Your boards are files on your own disk, so most of what a security page normally promises about somebody else's servers does not apply here.
Architecture
Most security pages describe how well a vendor guards your data on their servers. The better answer is for it not to be there.
Boards are written to your own disk and read from there. The primary copy is yours. The application works fully offline, and an outage on our side does not take your work away.
When cloud sync is on, board and workspace content is encrypted on your device with a key that is never transmitted to us. The server stores ciphertext it holds no key for. That is an inability to read rather than a promise not to. Your login and your invoice references are ordinary account data and are described in the privacy policy.
An administrator can disable cloud sync for the entire organisation, so nothing leaves the machines it was created on. Enforced by configuration, not by asking each person to remember.
Access is scoped per tenant and enforced server-side, not in the client. Relational data carries tenant authorisation at the storage layer.
Roles apply per workspace and narrow per project. Guests reach named projects only. Access is granted rather than inherited.
Security-relevant events are recorded and retained for 90 to 365 days depending on risk. This is what an incident review reads afterwards.
Single sign-on
It runs over SAML 2.0 with your own identity provider, and SCIM provisioning comes with it, so people who leave are deactivated from your directory rather than by somebody remembering. Tell us which provider you use and we set it up for your workspace. There is no form and no waiting list.
Operations
Transport
TLS everywhere. HSTS, nosniff, frame-deny, a strict Content-Security-Policy and a Referrer-Policy on this site.
At rest
Backups encrypted at rest on a rolling window of roughly 30 days.
Secrets
Production secrets live in the platform secret stores and are never committed to source control. This is enforced by a check in the release pipeline.
Authentication
Browser sessions use an HttpOnly, Secure, SameSite=Strict cookie. Tokens are deliberately not kept in local storage, where a script could read them.
Enterprise access
Single sign-on and SCIM provisioning, switched on for your workspace when you ask for it.
Dependencies
Code scanning and dependency review run in CI. Releases are gated on those checks passing.
Subprocessors
Published in full in the privacy policy, with the data category each one receives.
Retention and deletion
Defined per data class, with verified deletion within 30 days. See the retention table.
Side by side
Ten questions about custody rather than about paperwork. A tick is a yes, a half circle is a yes with the limit written under it, and a dash is a no.
| Question | WinnerCeyu | Miro | Asana | monday | Notion | ClickUp | Trello |
|---|---|---|---|---|---|---|---|
| Your boards are files on your own disk | ✓ | – | – | – | – | – | – |
| Cloud sync only you can read | ✓ | – | – | – | – | – | – |
| Opens and edits with no network at all | ✓ | – | – | – | ◐recent pages | ◐limited mode | – |
| One switch turns the cloud off for everyone | ✓ | – | – | – | – | – | – |
| Works without an account | ✓ | – | – | – | – | – | – |
| Single sign-on with SAML and SCIM | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Encrypted in transit and at rest | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Subprocessors published with the data each one receives | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| A written vulnerability disclosure policy | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Your data back out on every plan, the free one included | ✓ | ◐board by board | ✓ | ◐paid plans | ✓ | ✓ | ✓ |
| Score | 10 / 10 | 5 / 10 | 6 / 10 | 5 / 10 | 6 / 10 | 6 / 10 | 6 / 10 |
Every row is a product fact you can check by opening the tools, and the four at the bottom are ones everybody here passes. Independent certificates such as SOC 2 and ISO 27001 answer a different question from custody and are deliberately not scored above. Ceyu does not hold one today.
Vulnerability disclosure
Write to security@ceyu.org. Machine-readable contact details are at /.well-known/security.txt (RFC 9116).
Ask for a data processing agreement, a subprocessor list or a security questionnaire and you get a straight answer, including where the answer is “no”.