Your security is our foundation
Comprehensive transparency into our security practices, compliance standards, and commitment to protecting your data.
Status
Center
Security Practices
End-to-End Encryption
AES-256 encryption for data at rest, TLS 1.3 for data in transit. Zero-knowledge architecture for sensitive workloads.
SOC 2 Type II
Annually audited security controls covering availability, processing integrity, confidentiality, and privacy.
ISO 27001
Certified information security management system with continuous improvement and risk-based approach.
GDPR & NDPR Compliant
Full compliance with global data protection regulations. Data residency options available.
Penetration Testing
Quarterly third-party penetration testing and continuous vulnerability scanning.
Incident Response
24/7 security monitoring with defined incident response procedures and SLA commitments.
Security Metrics
99.99%
Uptime SLA
< 1hr
Incident Response
4
Pen Tests / Year
100%
Security Training
Compliance Standards
SOC 2 Type II
ISO 27001:2022
GDPR
NDPR
PCI DSS
HIPAA
Data Protection Commitment
We treat your data with the same care we'd want for our own. Our agreements define exactly how your data is handled, stored, and protected.
Security FAQ
Direct answers to the security questions enterprise clients ask before signing.
Client data is stored and processed exclusively within the residency region defined in your agreement — EU, US, or APAC — on certified infrastructure operated by our cloud partners AWS, Google Cloud, and Microsoft. Our remote-first team accesses production systems only through audited, ISO 27001-governed channels.
All data at rest is encrypted with AES-256, and every connection in transit is protected with TLS 1.3. Sensitive workloads can additionally be run under a zero-knowledge architecture on request.
We engage no sub-processor without your prior written consent. Any proposed third-party processor is disclosed in advance and must be approved in writing as an amendment to your agreement before it can touch your data.
Affected clients are notified through the direct CEO line — the same counsel channel every engagement runs on — with acknowledgment within 15 minutes per our SLA. Containment and remediation then proceed around the clock under our defined incident response procedures, followed by a full post-incident report.
On contract end, your data and deliverables are handled exactly as your agreement specifies: IP ownership transfers to you in full, escrowed materials are released, and all client data is deleted from our systems within the timeframe defined in the agreement. Certified deletion is available on request.
Responsible Disclosure
We welcome security researchers to report vulnerabilities. Our responsible disclosure program ensures rapid remediation.
Report a Vulnerability