Security at Polaris
Security is treated as an engineering responsibility, with clear statements about controls that exist today and work that remains ahead.
Last reviewed: 13 June 2026
Tenant isolation
Operational customer data is separated into PostgreSQL tenant schemas, while global identity and platform control data remains in the public control plane.
Private object storage
Attachments and raw inbound email are stored in private Amazon S3 buckets with public access blocked and encryption at rest enabled.
Least privilege
Production infrastructure is designed to use workload IAM roles and scoped permissions instead of long-lived application access keys.
Multi-factor authentication
Users can protect their global Polaris account with authenticator-app MFA and single-use recovery codes. Operations and Enterprise workspaces can require MFA for their members.
Account access protection
New users set their own password through expiring, single-use workspace invitations. Repeated failed sign-ins lock the account and alert workspace administrators.
Traceability
Important ticket, attachment, provisioning and configuration activity is designed to produce auditable operational records.
Secure delivery
The application uses authenticated attachment delivery and sanitises inbound email HTML before it is shown to agents.
Recovery foundations
Versioned object storage, durable inbound-email receipts and replayable processing provide foundations for recovery workflows.
Certifications and assurance
Polaris is not currently ISO 27001 certified and does not claim to be. As the service matures, we will document policies, risk management, incident response and supplier controls in a way that supports customer due diligence and makes future independent assurance achievable.
Planned security work
- Formal incident response and vulnerability disclosure processes.
- Single sign-on and stronger session-management controls.
- Documented backup restoration testing and retention controls.
- Independent security testing before broader availability.
Report a security concern
Please report suspected vulnerabilities or security incidents privately to security@helpana.io. Do not include customer data beyond what is necessary to explain the issue.