Legal
Security Information
An overview of Empire's approach to account protection, infrastructure security, access controls, data handling, and customer responsibility.
1. Scope of this page
This page describes the security approach used to operate Empire as a software platform. It is intended to provide practical information about account protection, infrastructure, and responsibilities.
2. Access control
Workspace access is controlled through account and application permissions. Customers are responsible for deciding who they authorise and for removing access when it is no longer needed.
Internal access to production systems and customer information is limited according to operational responsibilities and access controls.
3. Authentication
Authentication is handled using managed identity and application security controls. Passwords and authentication credentials are not intended to be visible to Empire staff in plain text.
Users should protect access to their email accounts, devices, and authentication methods because those systems may be used to access Empire.
4. Data in transit and at rest
Traffic between supported browsers and Empire is transmitted over encrypted connections.
Customer data is stored using managed infrastructure services that provide platform-level protections, including encryption capabilities and access controls.
5. Operational security
We use logging, monitoring, access controls, software updates, and other operational practices designed to maintain service reliability and help investigate suspicious activity.
Security controls evolve with the product, infrastructure, and threat environment.
6. Customer responsibility
Customers should use strong account security, grant only necessary user access, keep connected systems secure, review account activity, and avoid placing credentials or secrets into ordinary workspace fields.
7. Data portability
Where supported by the product, customers can export workspace information so their business records are not dependent on a single interface.
8. Reporting a vulnerability
Suspected vulnerabilities can be reported to support@empirekeep.com with the subject line "Security report".
Please provide enough technical detail to help reproduce and investigate the issue and allow a reasonable period for review before public disclosure.
9. Certifications and claims
We publish security certifications or independent assurance reports only when they have actually been obtained and are current.
The absence of a published certification should not be interpreted as a claim that Empire holds that certification. Questions about current security information can be sent to support@empirekeep.com.