Security & Trust

You're trusting us with sensitive employee data and certification documents. Security isn't a feature—it's the foundation of everything we build.

Last updated: July 2026

Infrastructure & Hosting

  • Hosted on Microsoft Azure, Railway, and Vercel with enterprise-grade infrastructure
  • 99.9% uptime target
  • Automated backups with point-in-time recovery
  • Quarterly disaster-recovery restore testing (most recent test: July 2026)

Data Encryption

  • Data at rest: AES-128 (Fernet) field-level encryption for stored OAuth credentials and integration secrets
  • Data in transit: TLS 1.3 for all connections
  • Field-level encryption: sensitive fields encrypted with Fernet symmetric encryption
  • Key management: encryption keys stored separately from encrypted data

Access Controls

  • Role-based access control (RBAC) for all users
  • Multi-factor authentication (TOTP) required for admin, manager, and other elevated roles
  • Account lockout after repeated failed login attempts
  • Organization-level data isolation
  • Session timeout and automatic logout

Compliance

  • Formal security controls in place: tamper-evident, hash-chained audit trail, role-based access controls, and a documented incident response plan
  • NIST CSF 2.0-aligned security program (self-assessed; documentation available on request)
  • Automated data retention/purge controls; account data export and deletion tools available on request today, with broader data-subject erasure and portability rights still being expanded
  • Incident response plan in place

Application Security

  • OWASP Top 10 vulnerability protection
  • Input validation and sanitization
  • SQL injection prevention
  • Cross-site scripting (XSS) protection
  • SameSite cookie policy and CSRF token defense-in-depth on all authenticated requests
  • Regular dependency scanning and updates

Employee & Process Security

  • Least privilege access principle
  • Documented security policies and procedures

Incident Response

In the unlikely event of a security incident, we have a documented incident response plan that includes immediate containment, stakeholder notification within 72 hours, root cause analysis, and remediation steps.

Found a Security Issue?

We appreciate responsible disclosure and will work with you to address any issues promptly.