Skip to main content
Security & Compliance

Security

Protecting your data is our top priority

SOC 2 Type II Certified

Compliance Certifications

We maintain the highest industry standards to keep your data safe and your business compliant.

Certified

SOC 2 Type II

Our infrastructure and operations undergo annual independent audits verifying strict data security controls, access management, and availability commitments.

Compliant

GDPR

Full compliance with EU General Data Protection Regulation, including data subject rights, lawful processing, and cross-border data transfer safeguards.

Compliant

HIPAA

Healthcare data protection measures meet HIPAA requirements, including administrative, physical, and technical safeguards for protected health information.

Certified

ISO 27001

Our information security management system is ISO 27001 certified, ensuring a systematic approach to managing sensitive company and customer information.

Compliant

PCI DSS

Payment card data is handled in accordance with PCI DSS standards, ensuring secure transmission, storage, and processing of cardholder information.

Compliant

CCPA

California Consumer Privacy Act compliance ensures California residents can access, delete, and opt out of the sale of their personal information.

Security Infrastructure

Multi-layered defenses built into every layer of our platform.

End-to-End Encryption

AES-256 encryption at rest and TLS 1.3 for all data in transit. Every byte of your data is encrypted — from the moment it leaves your browser to when it is stored on our servers.

Zero-Trust Architecture

Every request is authenticated and authorized regardless of network location. Micro-segmentation ensures lateral movement is impossible even if perimeter defenses are breached.

24/7 Threat Monitoring

Dedicated security operations team monitors all systems around the clock. Automated alerting and incident response playbooks ensure threats are neutralized within minutes.

Automated Vulnerability Scanning

Continuous automated scanning of our infrastructure and dependencies. Every deployment triggers security checks, and critical vulnerabilities are patched within 24 hours.

SOC 2 Annual Audits

Independent third-party auditors review our controls annually. Our SOC 2 Type II report covers security, availability, processing integrity, confidentiality, and privacy.

Bug Bounty Program

Our public bug bounty program incentivizes ethical hackers to discover and report vulnerabilities. We work with leading platforms to ensure responsible disclosure.

Data Residency

Your data stays in the region you choose. We never move or replicate customer data across regions without explicit consent.

🇺🇸

United States

Virginia

Primary region for North American customers

  • AWS us-east-1
  • SOC 2 & HIPAA audited
  • 99.99% uptime SLA
🇪🇺

European Union

Frankfurt

Dedicated region for EU data residency requirements

  • AWS eu-central-1
  • GDPR compliant
  • Data never leaves EU
🇳🇬

Africa

Lagos

Emerging region for African market customers

  • AWS af-south-1
  • Low-latency access
  • Growing compliance coverage
All regions run on isolated infrastructure with dedicated encryption keys

Responsible Disclosure

We believe in working with the security community. If you discover a vulnerability in our systems, we encourage you to report it responsibly. Our team will acknowledge your report within 24 hours and work with you to resolve the issue. We offer bounties and public recognition for valid findings.

Report a Bug

Security is not a feature — it's a foundation

Have questions about our security practices, compliance posture, or need a copy of our SOC 2 report?