Security Practices
Last Updated:
Data Encryption
All data transmitted between your devices and our servers is encrypted using TLS 1.3. Data at rest is encrypted using AES-256 encryption. Database backups are encrypted and stored in geographically separate locations. API keys and credentials are managed through a secrets management service and never stored in plaintext.
Infrastructure
Our platform runs on AWS infrastructure with multi-availability-zone redundancy. We use managed services for databases and caching to benefit from provider-level security patching and monitoring. Network access is restricted through security groups and private subnets, and all infrastructure changes go through code review and automated deployment pipelines.
Incident Response
We maintain a documented incident response plan that includes detection, containment, investigation, and resolution phases. Security incidents are triaged within one hour of detection. Affected customers are notified within 72 hours of a confirmed data breach. We conduct post-incident reviews to prevent recurrence and publish transparency reports as appropriate.
Subprocessors
We use a limited number of third-party subprocessors to deliver our services. These include AWS for cloud infrastructure, Resend for transactional email delivery, and Stripe for payment processing. Each subprocessor is vetted for security practices and bound by data processing agreements. We maintain an up-to-date list of subprocessors and notify customers of changes.