Security & Compliance
How we protect your data and maintain security standards
Last updated: October 20, 2025
Security Infrastructure
Encrypted Data Storage:
All data at rest is encrypted using AES-256 encryption
Secure Transmission:
All data in transit uses TLS 1.3 encryption
SOC 2 Certified Infrastructure:
Our cloud providers are SOC 2 Type II certified
Access Controls
- • Role-based access control (RBAC) for all user accounts
- • Two-factor authentication (2FA) available for all users
- • Audit logs for all data access and modifications
- • Automatic session timeout after 24 hours of inactivity
- • Password requirements: minimum 8 characters, mixed case, numbers
Monitoring & Response
- • 24/7 automated security monitoring
- • Real-time threat detection and alerting
- • Regular security audits and penetration testing
- • Incident response plan with defined SLAs
- • Regular security training for all team members
Data Protection
- • Daily automated backups with 30-day retention
- • Geo-redundant storage for disaster recovery
- • Regular backup integrity testing
- • Data deletion within 30 days of account closure
- • GDPR and CCPA compliant data handling
Vulnerability Disclosure
If you discover a security vulnerability, please report it to us immediately at:
[email protected]We take all reports seriously and will respond within 48 hours.