Ceyu

Trust centre

Your work stays yours.

Every control on this page is in the product today, and you can check each one by opening it. The strongest of them is also the simplest. Your boards are files on your own disk, so most of what a security page normally promises about somebody else's servers does not apply here.

Architecture

The strongest control is data that never leaves

Most security pages describe how well a vendor guards your data on their servers. The better answer is for it not to be there.

Local-first storage

Boards are written to your own disk and read from there. The primary copy is yours. The application works fully offline, and an outage on our side does not take your work away.

End-to-end encrypted sync

When cloud sync is on, board and workspace content is encrypted on your device with a key that is never transmitted to us. The server stores ciphertext it holds no key for. That is an inability to read rather than a promise not to. Your login and your invoice references are ordinary account data and are described in the privacy policy.

Workspace-wide local-only policy

An administrator can disable cloud sync for the entire organisation, so nothing leaves the machines it was created on. Enforced by configuration, not by asking each person to remember.

Tenant isolation

Access is scoped per tenant and enforced server-side, not in the client. Relational data carries tenant authorisation at the storage layer.

Least privilege

Roles apply per workspace and narrow per project. Guests reach named projects only. Access is granted rather than inherited.

Append-only audit trail

Security-relevant events are recorded and retained for 90 to 365 days depending on risk. This is what an incident review reads afterwards.

Single sign-on

We switch on single sign-on for you when you ask

It runs over SAML 2.0 with your own identity provider, and SCIM provisioning comes with it, so people who leave are deactivated from your directory rather than by somebody remembering. Tell us which provider you use and we set it up for your workspace. There is no form and no waiting list.

Operations

How it is run

Transport

TLS everywhere. HSTS, nosniff, frame-deny, a strict Content-Security-Policy and a Referrer-Policy on this site.

At rest

Backups encrypted at rest on a rolling window of roughly 30 days.

Secrets

Production secrets live in the platform secret stores and are never committed to source control. This is enforced by a check in the release pipeline.

Authentication

Browser sessions use an HttpOnly, Secure, SameSite=Strict cookie. Tokens are deliberately not kept in local storage, where a script could read them.

Enterprise access

Single sign-on and SCIM provisioning, switched on for your workspace when you ask for it.

Dependencies

Code scanning and dependency review run in CI. Releases are gated on those checks passing.

Subprocessors

Published in full in the privacy policy, with the data category each one receives.

Retention and deletion

Defined per data class, with verified deletion within 30 days. See the retention table.

Side by side

Where the work actually sits

Ten questions about custody rather than about paperwork. A tick is a yes, a half circle is a yes with the limit written under it, and a dash is a no.

Ceyu compared with Miro, Asana, monday.com, Notion, ClickUp and Trello on ten security questions
Question WinnerCeyu Miro Asana monday Notion ClickUp Trello
Your boards are files on your own disk
Cloud sync only you can read
Opens and edits with no network at all recent pages limited mode
One switch turns the cloud off for everyone
Works without an account
Single sign-on with SAML and SCIM
Encrypted in transit and at rest
Subprocessors published with the data each one receives
A written vulnerability disclosure policy
Your data back out on every plan, the free one included board by board paid plans
Score 5 / 10 6 / 10 5 / 10 6 / 10 6 / 10 6 / 10

Every row is a product fact you can check by opening the tools, and the four at the bottom are ones everybody here passes. Independent certificates such as SOC 2 and ISO 27001 answer a different question from custody and are deliberately not scored above. Ceyu does not hold one today.

Vulnerability disclosure

Found something? Tell us.

Write to security@ceyu.org. Machine-readable contact details are at /.well-known/security.txt (RFC 9116).

What we commit to

  • Acknowledgement within 3 working days
  • An initial assessment within 10 working days
  • Progress updates until it is closed
  • Credit in the release notes if you want it, and none if you do not
  • No legal action against good-faith research that follows the rules below

What we ask

  • Do not access, modify or delete data belonging to anyone else. Use your own test workspace.
  • Do not degrade the service, so no denial of service and no bulk automated scanning.
  • Give us a reasonable window to fix it before publishing. Ninety days is the norm, and if you need it shorter, tell us why.
  • Include enough detail to reproduce it. A proof of concept is worth ten paragraphs.

Need paperwork for procurement?

Ask for a data processing agreement, a subprocessor list or a security questionnaire and you get a straight answer, including where the answer is “no”.