Enterprise-grade protection for your business data
Secure cloud infrastructure with automated failover, daily encrypted backups retained 30 days. All servers are firewalled with restricted SSH access and automated security patching.
At rest: AES-256 for all data and backups. In transit: TLS 1.3 on all connections. Secrets: API keys, OAuth tokens stored in encrypted columns with application-layer decryption.
Every workspace is isolated. All queries scoped by tenant_id. Sessions, uploads, API keys, automation rules — all tenant-scoped. Cross-tenant access architecturally impossible.
RBAC: 4 roles with per-module, per-action granularity. Sessions: Server-side, HttpOnly cookies, inactivity expiry. Passwords: bcrypt + salt, email-verified reset.
Auth via X-Internal-Key or session token. 100 req/min rate limit. All access logged. Keys scoped per module, revocable.
Every critical action logged with timestamp, user, IP, action, entity. Retained 12 months, tamper-resistant.
SLAs: Critical (1h), High (4h), Medium (24h). Customer notification within 72h of confirmed breaches.
Only established providers: Razorpay (PCI-DSS), Meta (SOC 2), Cloudinary (SOC 2), Resend. Minimum-data principle.
Dependency CVE monitoring. Input validation, output encoding (XSS/SQLi). CSRF on all forms. Uploads type-checked, stored outside web root.
Report vulnerabilities: [email protected]. Acknowledged within 24h, resolution timeline within 72h.