Security

Your data security is our top priority. We implement industry-leading security practices to protect your information.

Encryption at Rest

All data encrypted using AES-256-GCM encryption standard

Encryption in Transit

TLS 1.3 for all network communications

Multi-Tenant Isolation

Strict org_id filtering prevents data leakage

Access Controls

Role-based access control (RBAC) and least privilege principles

SOC 2 Type II

Annual third-party security audits and compliance

Incident Response

72-hour notification for any security breaches

Infrastructure Security

  • Cloud Hosting: AWS with automatic backups and disaster recovery
  • Database: ArangoDB Cloud with encryption and access controls
  • Network Security: Virtual Private Cloud (VPC) isolation
  • Rate Limiting: 60 requests/minute per organization to prevent abuse

Authentication & Authorization

  • OAuth 2.0: Industry-standard authentication with secure token management
  • Token Rotation: Automatic refresh 10 minutes before expiry
  • Read-Only Access: We request minimal OAuth scopes (no write permissions)
  • Multi-Factor Authentication: Available through Auth0

Compliance & Auditing

  • SOC 2 Type II: Annual third-party security audits
  • GDPR Compliant: Full data protection compliance for EU customers
  • CCPA Compliant: California privacy law compliance
  • Penetration Testing: Regular security assessments

Data Protection

  • Data Minimization: We only collect data necessary for service functionality
  • Automatic Cleanup: Expired tokens and cache are automatically deleted
  • Secure Deletion: Complete data erasure upon account deletion
  • No Data Sales: We never sell your data to third parties

Incident Response

In the event of a security incident:

  1. Immediate containment and investigation
  2. Affected users notified within 72 hours
  3. Platform providers notified within 48 hours
  4. Detailed incident report provided
  5. Remediation steps and prevention measures implemented

Report Security Issues

If you discover a security vulnerability, please report it immediately to: [email protected]

We take all security reports seriously and will respond within 24 hours.