Skip to content
Graniite

Security

Last updated: August 24, 2026

How your library is protected

Per-user isolation, enforced by the database. Every row of your content carries your identity, and Postgres row-level security policies enforce that boundary on every query. Isolation is not an application habit here; it is a database rule.

Encrypted in transit and at rest. All traffic runs over TLS, and your data is encrypted at rest by our infrastructure providers (Supabase and Vercel).

Audited before launch. Graniite went through a dedicated pre-launch security audit. Every critical finding was closed before public signup opened, and the audit trail lives in the codebase where it keeps future changes honest.

Your content is yours

We never train AI models on your content. Your library exists to serve you, not to become training data.

Export anytime, delete in one click. Your account settings include a full export of everything you have saved, and an account deletion that removes your content from our systems, cancels billing, and scrubs personal details from our payment processor.

Transparent vendors. Every third party that touches your data is listed on our sub-processors page. We do not sell your data. Ever.

Plain talk

Some things we deliberately do not claim: Graniite is not end-to-end encrypted, not zero-knowledge, and not SOC 2 certified today. Those are real engineering and audit commitments, and we would rather tell you exactly where we stand than borrow language we have not earned yet. As our posture grows, this page grows with it.

Reporting a vulnerability

Found something? We want to know. Email team@graniite.co, or see our security.txt. We read every report and respond to genuine findings.

Back to home
Security · Graniite