Security is infrastructure, not a feature.
We treat your data the way we treat our own: with paranoia, redundancy, and zero tolerance for shortcuts.
Encryption at Rest
All client data is encrypted at rest with AES-256 through our managed database platform, using cloud-provider-managed keys. Disk-level encryption is enabled by default across all production systems.
Encryption in Transit
All data in transit is protected by TLS 1.3. We enforce HTTPS across all endpoints and reject connections using older, insecure protocols.
Access Control
We enforce role-based access control (RBAC) with the principle of least privilege. Access to production systems is restricted to authorized staff and scoped to what each role requires.
Vulnerability Management
We run continuous automated dependency and vulnerability scanning across our systems, and remediate findings on a severity-prioritized basis.
Data Residency
Client data is stored in AWS US-East-1 by default. EU data residency is available for clients with applicable compliance requirements. Data is never replicated outside of agreed regions without explicit written consent.
Vendor Risk
All sub-processors and third-party vendors are reviewed for security posture before engagement. We maintain a current list of sub-processors and notify clients of material changes. Vendors with access to client data must meet our minimum security baseline.
Found a vulnerability?
We take security reports seriously and respond to all credible submissions. If you've identified a vulnerability in our platform or infrastructure, please report it to us privately. We commit to acknowledging reports within 24 hours and providing a status update within 5 business days.
We do not take legal action against researchers who report vulnerabilities in good faith and give us a reasonable opportunity to remediate before public disclosure. We offer recognition and, for critical findings, financial rewards at our discretion.