Encryption, MFA, audit logs, and SOC 2 readiness — built into the product, not bolted on.
TLS 1.3 in transit, AES-256-GCM field-level encryption for sensitive data in the application, and AES-256 encryption at rest at the infrastructure layer.
Bcrypt-hashed passwords, JWT access tokens with refresh rotation, optional MFA via TOTP, SMS, or WebAuthn passkeys, and SSO/SAML on Enterprise.
Every privileged action is recorded with actor, action, resource, IP, user-agent, and timestamp. Logs are immutable and exportable.
Strict CSP, secure HTTP headers, rate limiting, and isolated environments. Production deploys are zero-downtime, signed, and rolled back automatically on failure.
Secret, static-analysis (SAST), and dependency scanning run on every build, alongside automated security patches and a published responsible-disclosure policy. We follow OWASP Top 10 and v3 enterprise security standards.
Built for GDPR, CCPA, India DPDP, PCI DSS (SAQ-A), and the EU AI Act — with SOC 2 and ISO 27001 / 42001 readiness baked in. See the honest, per-framework status on our Compliance page.
A non-exhaustive list of what's enforced today.
Found a vulnerability? Please report it confidentially before public disclosure. We acknowledge reports within 2 business days and aim to remediate within 30 days for high-severity issues.
See also our Compliance & Certifications, Privacy Policy, Terms of Service, and Trust Center.