Security & Trust

Built secure from the ground up

We treat security as a product feature, not a checkbox. Here is what we do to protect your data and your customers.

Compliance & Certifications

SOC 2 Type II
Annually audited
GDPR
EU data protection
ISO 27001
Information security
PCI DSS
Payment card security

How we protect your data

Encryption

All data is encrypted at rest and in transit using industry-standard algorithms.

  • AES-256 encryption at rest
  • TLS 1.3 in transit
  • Key rotation every 90 days

Access Control

Least-privilege access enforced across the entire platform.

  • Role-based access control
  • Hardware MFA for all staff
  • Zero-trust network architecture

Audit Logging

Every action is recorded in an immutable, timestamped audit trail.

  • Immutable audit log
  • Exportable in JSON / CSV
  • 90-day retention (enterprise: 1 year)

Infrastructure

Hardened cloud infrastructure with continuous security scanning.

  • SOC 2 Type II certified cloud
  • Daily vulnerability scanning
  • Automated patch management

Network Security

Layered network controls to detect and block threats in real time.

  • DDoS mitigation
  • WAF with custom rulesets
  • Egress filtering & IP allowlists

Disaster Recovery

Multi-region redundancy and tested recovery procedures.

  • RPO < 1 hour, RTO < 4 hours
  • Cross-region failover
  • Quarterly DR drills

Responsible Disclosure

Found a vulnerability? We take security reports seriously and respond within 48 hours. Please do not publicly disclose until we have had a chance to address the issue.