Reference

Security and privacy

How companies are kept apart, what Gridline never reads, and how secrets are stored.

A company hands Gridline its spreadsheets, so how they are kept safe is part of the product. This page says plainly what Gridline does, so you can judge it, in the same simple language as everything else.

Companies are kept apart

  • Everything Gridline stores belongs to one company, and every read and write is limited to the company of the person asking.
  • The company comes from who you are, never from the request. You cannot ask for another company's data by sending its id: a request that tries is simply refused.
  • Another company's data is not "forbidden", it is 404. Nothing reveals that it exists.

People are kept apart, too

  • Inside a company, a restricted file is visible only to its uploader, admins and the people it is shared with. One rule decides this everywhere: lists, reports, downloads, comments, GraphQL, live updates and AI agents.
  • Your role and your company's status are read fresh on every request, so removing someone or suspending a company works immediately, with no token to wait out.
  • Sign-in, password reset and activation never reveal whether an email address has an account.

Passwords and tokens

  • Passwords are stored with scrypt, a deliberately slow function. Gridline never stores a password, or anything that could be turned back into one.
  • One-time links (activation, invitation, password reset) and refresh tokens are random, and only a hash is stored. A link works once.
  • Refresh tokens rotate. Using an old one again is treated as theft and ends the session.
  • API keys are shown once and stored as a hash. A leaked key can be revoked, and it can never mint a new key or reach account settings.
  • Access tokens carry only who you are, are pinned to one signing algorithm, and expire after 15 minutes.

Your files

  • Files live in a private storage bucket. They are never served through a public address. A download is a link that works for 5 minutes, handed out only after the access check.
  • Gridline decides what a file is from its bytes, so a disguised program is refused whatever it is named.
  • Files are read by a profiler with limits (rows, columns, and a guard against files that expand enormously), so one bad file cannot take the service down.
  • Legacy .xls files are stored but not profiled, because the only parsers for that format have a history of security problems.

What the AI sees

If a plain-language summary is switched on, the model is shown aggregates only: column names, counts, percentages, and the average of a numeric column. It never sees a row or a cell value, and it is told to treat column names as data, not instructions. A failed or unavailable model never stops a report.

Payments

  • Card details are entered only on Stripe's hosted pages. Gridline never sees or stores a card number.
  • Stripe's own events change your plan, after Gridline verifies their signature. A payment event cannot be replayed or applied twice.

Webhooks

  • Every delivery is signed with HMAC-SHA256 over the timestamp and the exact body, so a receiver can prove it came from Gridline and reject replays.
  • Secrets are encrypted at rest.
  • Every attempt re-resolves the address, refuses private and internal networks, pins the checked address for the connection, and never follows redirects.

A record you can trust

  • Every change writes an audit entry in the same step as the change. The table is append-only at the database level.
  • Logs redact tokens, one-time links and secrets, and every line carries a correlation id so a problem can be traced end to end.

Throttling

Requests are limited per company, and sensitive actions (sign-in, reset, registration) have small limits of their own per address. Sign-in does the same amount of work for a wrong password as for an unknown email, so timing reveals nothing.