Security & Trust
Built secure from the ground up
We treat security as a product feature, not a checkbox. Here is what we do to protect your data and your customers.
Compliance & Certifications
SOC 2 Type II
Annually audited
GDPR
EU data protection
ISO 27001
Information security
PCI DSS
Payment card security
How we protect your data
Encryption
All data is encrypted at rest and in transit using industry-standard algorithms.
- AES-256 encryption at rest
- TLS 1.3 in transit
- Key rotation every 90 days
Access Control
Least-privilege access enforced across the entire platform.
- Role-based access control
- Hardware MFA for all staff
- Zero-trust network architecture
Audit Logging
Every action is recorded in an immutable, timestamped audit trail.
- Immutable audit log
- Exportable in JSON / CSV
- 90-day retention (enterprise: 1 year)
Infrastructure
Hardened cloud infrastructure with continuous security scanning.
- SOC 2 Type II certified cloud
- Daily vulnerability scanning
- Automated patch management
Network Security
Layered network controls to detect and block threats in real time.
- DDoS mitigation
- WAF with custom rulesets
- Egress filtering & IP allowlists
Disaster Recovery
Multi-region redundancy and tested recovery procedures.
- RPO < 1 hour, RTO < 4 hours
- Cross-region failover
- Quarterly DR drills
Responsible Disclosure
Found a vulnerability? We take security reports seriously and respond within 48 hours. Please do not publicly disclose until we have had a chance to address the issue.