// Security
Your security is our top priority. We implement industry-leading security practices to protect your data and infrastructure.
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Your secrets and credentials are stored in encrypted vaults.
Enterprise-grade authentication with SSO/SAML support, multi-factor authentication, and role-based access control (RBAC).
Private networking, VPC peering, IP allowlisting, and DDoS protection to keep your infrastructure secure.
Complete tenant isolation with dedicated resources. Your data is never shared or accessible by other customers.
SOC 2 Type II certified. GDPR compliant. Regular third-party security audits and penetration testing.
Continuous vulnerability scanning, automated patching, and a responsible disclosure program for security researchers.
Hosted on SOC 2 compliant cloud providers (AWS, GCP, Azure)
Kubernetes clusters hardened following CIS benchmarks
Regular infrastructure security assessments
Automated security updates and patching
Network segmentation and micro-segmentation
Secure software development lifecycle (SSDLC)
Static and dynamic application security testing
Dependency vulnerability scanning
Code review and security-focused PR reviews
Regular penetration testing by third parties
24/7 security monitoring and alerting
Incident response team and procedures
Comprehensive audit logging
Background checks for all employees
Security awareness training for staff
Encryption at rest and in transit
Regular automated backups
Disaster recovery procedures
Data retention and deletion policies
GDPR data subject rights support
SOC 2 Type II
Annual audit of security, availability, and confidentiality controls
GDPR
Full compliance with EU data protection regulations
ISO 27001
Information security management system certification (in progress)
We appreciate the security research community. If you discover a security vulnerability, please report it responsibly to our security team.
[email protected]