Security
Technical security controls protecting your data at every layer.
Last updated: July 2026
Encryption
Data at Rest
AES-256 encryption for all stored data, including database, backups, and file storage.
Data in Transit
TLS 1.3 for all network communication. HSTS enforced. No plaintext transmission.
Key Management
AWS KMS with automatic key rotation. Keys never exposed to application code.
Field-Level Encryption
Additional encryption layer for sensitive fields like SSN, when applicable.
Access Control
- Row-level security enforced at database level, not just application
- Role-based access control with principle of least privilege
- Multi-factor authentication available for all users
- SSO integration (SAML 2.0, OpenID Connect) for enterprise customers
- Session management with configurable timeouts
- IP allowlisting available for enterprise deployments
Infrastructure Security
- Hosted on AWS with SOC 2 Type II certified infrastructure
- Network segmentation with private subnets for data tier
- Web Application Firewall (WAF) with managed rule sets
- DDoS protection via AWS Shield
- Automated vulnerability scanning (weekly)
- Annual third-party penetration testing
Incident Response
- Documented incident response plan with defined roles
- Security monitoring and alerting (24/7)
- Breach notification within 72 hours as required by law
- Post-incident review and remediation tracking
- Annual tabletop exercises and plan updates
Security questions?
Our security team is available to discuss your specific requirements.