Security Policy

Our commitment to protecting your data and operations

Data Encryption

  • TLS 1.3: All data in transit is encrypted using industry-standard TLS 1.3
  • AES-256: Data at rest encrypted with AES-256 encryption
  • Key Management: Encryption keys managed through secure key management systems
  • Certificate Pinning: SSL certificate pinning for enhanced security

Access Control

  • Multi-Factor Authentication (MFA): Supported for all user accounts
  • Role-Based Access Control (RBAC): Granular permissions based on user roles
  • Single Sign-On (SSO): Enterprise SSO support available
  • Session Management: Secure session tokens with automatic expiration
  • Password Policies: Strong password requirements and regular rotation

Security Monitoring

  • 24/7 Monitoring: Continuous security monitoring and threat detection
  • Intrusion Detection: Advanced IDS/IPS systems
  • Logging & Auditing: Comprehensive audit logs of all system activities
  • Anomaly Detection: AI-powered anomaly detection for suspicious activities
  • Incident Response: Dedicated security team for rapid incident response

Infrastructure Security

  • Secure Data Centers: Tier III+ certified facilities with physical security
  • Network Security: Firewalls, DDoS protection, and network segmentation
  • Regular Backups: Encrypted daily backups with point-in-time recovery
  • Disaster Recovery: Comprehensive disaster recovery and business continuity plans
  • Vulnerability Management: Regular security assessments and penetration testing

Security Best Practices

For Users:

  • Enable multi-factor authentication on your account
  • Use strong, unique passwords
  • Regularly review your account activity and access logs
  • Report suspicious activities immediately
  • Keep your devices and browsers updated
  • Be cautious with sharing credentials or API keys

Compliance & Certifications

We maintain compliance with:

  • SOC 2 Type II: Annual security audits and certifications
  • ISO 27001: Information security management standards
  • GDPR: General Data Protection Regulation compliance
  • CCPA: California Consumer Privacy Act compliance
  • NIST Framework: Cybersecurity framework alignment

Security Incident Reporting

If you discover a security vulnerability or incident, please report it immediately:

Security Email: [email protected]

Responsible Disclosure: We follow responsible disclosure practices

Response Time: Critical issues: 24 hours | High severity: 72 hours

Please include: Description of the issue, steps to reproduce, potential impact, and your contact information.

Data Breach Response

In the event of a data breach, we will:

  • Immediately contain and mitigate the breach
  • Assess the scope and impact
  • Notify affected users within 72 hours (as required by law)
  • Report to relevant data protection authorities
  • Provide transparent communication and remediation steps
  • Conduct post-incident review and implement improvements

Third-Party Security

We carefully vet and monitor third-party services:

  • Security assessments of all vendors
  • Regular vendor security audits
  • Data processing agreements with security requirements
  • Continuous monitoring of third-party security posture

Contact Security Team

Security Team: [email protected]

General Inquiries: [email protected]

Address: Sycek OSINT, Bangalore KA, INDIA