Your incident data is sensitive. We treat security as a core feature, not an afterthought.
Multiple layers of security to protect your data at every level.
All data protected with industry-standard encryption.
Fine-grained permissions and authentication.
Complete visibility into all system activity.
Multiple layers of network protection.
Proactive security testing and monitoring.
Prepared to handle security events.
We maintain industry certifications and follow security best practices.
We host on AWS in EU-West-2 (London) with VPC isolation, security groups, and infrastructure-as-code via Terraform. All infrastructure changes go through code review and automated security scanning. We use immutable deployments with no direct server access.
We follow OWASP guidelines and secure coding practices. All code goes through peer review and automated SAST/DAST scanning. We use parameterised queries, input validation, and output encoding throughout. Dependencies are monitored and patched promptly.
Customer data is encrypted at rest using AES-256 and in transit using TLS 1.3. Database access requires certificate authentication. Backups are encrypted and tested regularly. We support configurable data retention and secure deletion on request.
All employees undergo background checks and security training. Access to production systems requires MFA and is logged. We follow the principle of least privilegeβemployees only have access to what they need. Access is reviewed quarterly.
We carefully vet all third-party vendors before onboarding. Sub-processors are listed in our DPA and undergo security assessment. We maintain a vendor inventory and review security postures annually. Data processing agreements are in place with all vendors.
We run 24/7 security monitoring with automated alerts for suspicious activity. Intrusion detection systems monitor for anomalies. All security events are logged to a SIEM for analysis. We maintain runbooks for common security scenarios.
Hosted on AWS with enterprise-grade infrastructure.
Our security team is happy to answer questions and provide documentation.