Skip to main content
Trust

Your security is our foundation

Comprehensive transparency into our security practices, compliance standards, and commitment to protecting your data.

Security

Security Practices

End-to-End Encryption

AES-256 encryption for data at rest, TLS 1.3 for data in transit. Zero-knowledge architecture for sensitive workloads.

SOC 2 Type II

Annually audited security controls covering availability, processing integrity, confidentiality, and privacy.

ISO 27001

Certified information security management system with continuous improvement and risk-based approach.

GDPR & NDPR Compliant

Full compliance with global data protection regulations. Data residency options available.

Penetration Testing

Quarterly third-party penetration testing and continuous vulnerability scanning.

Incident Response

24/7 security monitoring with defined incident response procedures and SLA commitments.

By The Numbers

Security Metrics

99.99%

Uptime SLA

< 1hr

Incident Response

4

Pen Tests / Year

100%

Security Training

Compliance

Compliance Standards

SOC 2 Type II

CertifiedSince 2026

ISO 27001:2022

CertifiedSince 2026

GDPR

CompliantSince 2026

NDPR

CompliantSince 2026

PCI DSS

Level 1Since 2026

HIPAA

CompliantSince 2026
Data Protection

Data Protection Commitment

We treat your data with the same care we'd want for our own. Our agreements define exactly how your data is handled, stored, and protected.

Source code escrow with independent trustee
Data residency options (EU, US, APAC)
Regular data disposal audits
Employee security training program
Background checks for all engineers
NDA coverage for all team members
Security FAQ

Security FAQ

Direct answers to the security questions enterprise clients ask before signing.

Client data is stored and processed exclusively within the residency region defined in your agreement — EU, US, or APAC — on certified infrastructure operated by our cloud partners AWS, Google Cloud, and Microsoft. Our remote-first team accesses production systems only through audited, ISO 27001-governed channels.

All data at rest is encrypted with AES-256, and every connection in transit is protected with TLS 1.3. Sensitive workloads can additionally be run under a zero-knowledge architecture on request.

We engage no sub-processor without your prior written consent. Any proposed third-party processor is disclosed in advance and must be approved in writing as an amendment to your agreement before it can touch your data.

Affected clients are notified through the direct CEO line — the same counsel channel every engagement runs on — with acknowledgment within 15 minutes per our SLA. Containment and remediation then proceed around the clock under our defined incident response procedures, followed by a full post-incident report.

On contract end, your data and deliverables are handled exactly as your agreement specifies: IP ownership transfers to you in full, escrowed materials are released, and all client data is deleted from our systems within the timeframe defined in the agreement. Certified deletion is available on request.

Responsible Disclosure

We welcome security researchers to report vulnerabilities. Our responsible disclosure program ensures rapid remediation.

Report a Vulnerability