Security Overview
Access Controls
- Role‑based access with least‑privilege by default; access is provisioned on business need and reviewed periodically.
- Multi‑factor authentication (MFA) enforced on core systems and cloud consoles where supported.
- Credential hygiene: unique SSO accounts, strong password policies, short‑lived tokens/keys, and immediate revocation on role changes.
- Environment separation for staging vs. production; restricted shell/database access to production.
Encryption
- In transit: TLS for public endpoints and managed services; modern ciphers preferred.
- At rest: platform‑level encryption for databases, volumes, and object storage where supported and appropriate.
- Key management: cloud‑native KMS or provider encryption; limited key access aligned to roles.
Backups & Disaster Recovery
- Automated backups (frequency and retention set per engagement); integrity checks on restore.
- Restore testing during onboarding and periodically for critical data stores.
- Documented recovery procedures; RPO/RTO targets defined by plan/architecture (e.g., single‑AZ vs. multi‑AZ/HA).
Monitoring & Logging
- Synthetic uptime checks and health probes on critical endpoints.
- Infrastructure/application metrics and alerting for errors, latency, saturation, and availability.
- Access and change logs retained for investigation and service quality; time‑synchronized systems.
Vulnerability & Patch Management
- Regular dependency updates and security patching; critical patches expedited.
- Scanning for known vulnerabilities in key components; risk‑based remediation timelines.
- Configuration hardening baselines for OS, network, and runtime; principle of minimal exposure.
Secure Development & Change Management
- Version control with protected branches, code reviews, and CI checks for changes.
- Staging environments and change windows for production releases; rollback plans for major updates.
- Secrets management via environment variables, vaults, or platform secrets; no secrets in code.
Incident Response
- Defined incident types and severities with on‑call escalation for P1/P2 events (plan‑dependent).
- Containment first: isolate affected components, rotate secrets, restore from clean backups if needed.
- Customer notifications for material incidents after initial containment; post‑incident review for P1/P2.
Data Protection & Privacy
- Processing aligned with customer instructions and applicable laws; no sale of personal data.
- Data Processing Addendum (DPA) available, including transfer safeguards where required.
- Cookie and privacy practices documented publicly; consent respected where applicable.
Vendor & Sub‑processor Oversight
- Use of reputable cloud and service providers; review of security posture and terms before onboarding.
- Sub‑processor list available on request; contractual obligations mirror our security/privacy standards.
Network & Application Protections
- Network segmentation and security groups; least‑exposed ports and protocols.
- CDN/WAF options for DDoS mitigation and layer‑7 filtering (plan‑dependent).
- Rate limiting, input validation, and headers/best practices for common web vectors.
Shared Responsibility
- We manage the underlying platform, tooling, and agreed operational controls.
- Customers manage application logic, content, user access within their tenant, and third‑party integrations.
- Guidance provided during onboarding: hardening, MFA, password policies, and least‑privilege roles.
Compliance & Assurance
- Security aligned to industry best practices suitable for SMB/enterprise web workloads.
- If your project requires specific attestations (e.g., ISO 27001, SOC 2) or region‑locking, we can scope hosting on compliant infrastructure and document shared controls.
Contact
Questions about security, incident reports, or requests for our sub‑processor list: [email protected]