Security & Trust
You're trusting us with sensitive employee data and certification documents. Security isn't a feature—it's the foundation of everything we build.
Last updated: July 2026
Infrastructure & Hosting
- Hosted on Microsoft Azure, Railway, and Vercel with enterprise-grade infrastructure
- 99.9% uptime target
- Automated backups with point-in-time recovery
- Quarterly disaster-recovery restore testing (most recent test: July 2026)
Data Encryption
- Data at rest: AES-128 (Fernet) field-level encryption for stored OAuth credentials and integration secrets
- Data in transit: TLS 1.3 for all connections
- Field-level encryption: sensitive fields encrypted with Fernet symmetric encryption
- Key management: encryption keys stored separately from encrypted data
Access Controls
- Role-based access control (RBAC) for all users
- Multi-factor authentication (TOTP) required for admin, manager, and other elevated roles
- Account lockout after repeated failed login attempts
- Organization-level data isolation
- Session timeout and automatic logout
Compliance
- Formal security controls in place: tamper-evident, hash-chained audit trail, role-based access controls, and a documented incident response plan
- NIST CSF 2.0-aligned security program (self-assessed; documentation available on request)
- Automated data retention/purge controls; account data export and deletion tools available on request today, with broader data-subject erasure and portability rights still being expanded
- Incident response plan in place
Application Security
- OWASP Top 10 vulnerability protection
- Input validation and sanitization
- SQL injection prevention
- Cross-site scripting (XSS) protection
- SameSite cookie policy and CSRF token defense-in-depth on all authenticated requests
- Regular dependency scanning and updates
Employee & Process Security
- Least privilege access principle
- Documented security policies and procedures
Incident Response
In the unlikely event of a security incident, we have a documented incident response plan that includes immediate containment, stakeholder notification within 72 hours, root cause analysis, and remediation steps.