Skip to content
Empire

Legal

Security Information

An overview of Empire's approach to account protection, infrastructure security, access controls, data handling, and customer responsibility.

Last updated: September 10, 20269 sectionsempirekeep.com/legal/security

1. Scope of this page

This page describes the security approach used to operate Empire as a software platform. It is intended to provide practical information about account protection, infrastructure, and responsibilities.

2. Access control

Workspace access is controlled through account and application permissions. Customers are responsible for deciding who they authorise and for removing access when it is no longer needed.

Internal access to production systems and customer information is limited according to operational responsibilities and access controls.

3. Authentication

Authentication is handled using managed identity and application security controls. Passwords and authentication credentials are not intended to be visible to Empire staff in plain text.

Users should protect access to their email accounts, devices, and authentication methods because those systems may be used to access Empire.

4. Data in transit and at rest

Traffic between supported browsers and Empire is transmitted over encrypted connections.

Customer data is stored using managed infrastructure services that provide platform-level protections, including encryption capabilities and access controls.

5. Operational security

We use logging, monitoring, access controls, software updates, and other operational practices designed to maintain service reliability and help investigate suspicious activity.

Security controls evolve with the product, infrastructure, and threat environment.

6. Customer responsibility

Customers should use strong account security, grant only necessary user access, keep connected systems secure, review account activity, and avoid placing credentials or secrets into ordinary workspace fields.

7. Data portability

Where supported by the product, customers can export workspace information so their business records are not dependent on a single interface.

8. Reporting a vulnerability

Suspected vulnerabilities can be reported to support@empirekeep.com with the subject line "Security report".

Please provide enough technical detail to help reproduce and investigate the issue and allow a reasonable period for review before public disclosure.

9. Certifications and claims

We publish security certifications or independent assurance reports only when they have actually been obtained and are current.

The absence of a published certification should not be interpreted as a claim that Empire holds that certification. Questions about current security information can be sent to support@empirekeep.com.