Tablewidewiki + diagrams
Pricing Leaving Confluence Security Claim a founding spot

Security at Tablewide

Last updated: September 30, 2026

We built Tablewide to hold team documentation, diagrams and API references, and not much else. Holding less sensitive data is our first security measure. This page describes what we do to protect your data, in plain language.

What we don't store

  • Passwords. Everyone signs in with a Google or Microsoft account: your team with your company's Google Workspace or Microsoft Entra ID, and invited guests with their own account. We never see or store passwords, and we don't run an identity provider. When you remove someone from your directory, or remove a guest's invitation, they can no longer sign in.
  • Card numbers. Stripe processes payments. We see only the card brand and last four digits.
  • Sensitive data. Our terms don't allow health records, payment card data, government IDs, passwords or secrets, children's data, or anything that needs HIPAA or PCI compliance. The Service isn't designed for that data, and we don't sign agreements for it.

Your data is kept separate

  • One company, one container, one database. Each customer runs in its own application container with its own database. No customer's data sits in another customer's database.
  • Region. Workspaces are hosted in the US. An EU region (Germany/Finland) is available on request. Your workspace and its backups stay in the region where they are hosted.

Encryption

  • In transit: all connections use HTTPS (TLS 1.2 or newer).
  • At rest: backups are encrypted with a separate key per customer. Live servers run in our hosting provider's secured data centres.
  • Backups: encrypted on our servers before upload, with a separate key for each customer. The backup storage provider cannot read them.

Backups and recovery

  • Nightly backups go to a second storage provider in the same region and are kept about 30 days. They can't be deleted early, even by us.
  • Every month we test a restore from backup to make sure backups actually work.
  • You can export your content yourself at any time. We recommend keeping your own exports; backups are our safety net, not a replacement for yours.

Who can access your data

  • Least privilege. Access to servers is limited to the people and tools that need it, with individual keys, and reviewed regularly.
  • Multi-factor authentication is required on every administrative account we use: hosting, backups, billing, email and code.
  • Logging. Administrative access and actions on production systems are logged.

AI operators

We run much of our operations with AI agents (Claude, from Anthropic), supervised by a human. Here is how that works:

  • AI agents have no standing access to your content. They access it only to carry out a migration or support request you asked for, and only what that request needs.
  • EU region: AI agents access your content only if you consent for that specific request. Otherwise a request is handled without them.
  • US region: you can ask for any request to be handled without AI access to your content.
  • AI agents cannot delete your data or backups without a human approving it.
  • Their actions on our systems are logged, and the AI provider does not train its models on data we send it.

Keeping software up to date

  • Operating systems and containers are updated at least monthly.
  • Critical security fixes are applied within 72 hours of a fix being available; high-severity fixes within 7 days.
  • We follow security advisories for BookStack, draw.io and the other open-source software we run.

If something goes wrong

We have a written incident response plan. If a security incident affects your personal data, we will tell your workspace admins without undue delay, and within 48 hours of confirming it, with what we know and what we're doing about it.

Compliance: what we have and what we don't

We are a small, new company and do not have a SOC 2 report or ISO 27001 certification yet. Instead of a certification, we offer:

  • a Data Processing Agreement covering GDPR (including Standard Contractual Clauses), UK GDPR and CCPA, included in our terms automatically;
  • a public list of subprocessors, with 30 days' notice of changes;
  • this page; and
  • written answers to your security questionnaire on request. Email [email protected].

Report a vulnerability

If you think you've found a security issue, email [email protected]. Please include steps to reproduce, and give us reasonable time to fix it before disclosing it publicly. We will acknowledge your report within 3 business days and keep you updated.

When testing, please only use a workspace you own, don't access or change other customers' data, and don't run denial-of-service or high-volume automated scans. If you follow these rules in good faith, we won't pursue legal action against you for your research. We don't run a paid bug bounty at this time.

Questions about security: [email protected].

Pricing Security and data Terms Privacy Refunds Subprocessors Open source Service status Confluence end of life Export a Confluence space vs Confluence Cloud vs Notion Hosted vs self-hosted BookStack Support: [email protected] Security: [email protected] Privacy: [email protected]

Aaron Vontell, an individual doing business as Tablewide. Mailing address to come.

Tablewide runs BookStack, the open source wiki, for you. We are not affiliated with or endorsed by the BookStack project. Confluence, Jira and Trello are trademarks of Atlassian; Notion is a trademark of Notion Labs. We mention them only to compare.