Trust Center
Transparency into how we protect your data with enterprise-grade security, privacy-first architecture, and continuous compliance monitoring.
Last updated: 10/11/2025 at 3:26:04 AM
Compliance & Certifications
Implemented Controls:
- Cookie consent management with granular opt-in/opt-out
- Data export & erasure APIs (Right to Access/Erasure)
- PII anonymization using SHA-256 hashing
- Privacy-preserving rate limiting (no IP storage)
- 90-day audit retention with configurable policies
- Privacy-first architecture with data minimization
Security Controls
AES-256-CBC encryption for sensitive data at rest, TLS 1.2+ for all data in transit
TOTP-based 2FA with encrypted secrets, backup codes, and account recovery options
Anonymous IP tracking, PII minimization, zero-knowledge design, GDPR-compliant by default
Shodan integration for attack surface management, CVE tracking, and vulnerability assessment
Comprehensive audit logs, forensic investigation tools, and 24/7 anomaly detection
Automated HIPAA, PCI DSS, GDPR, and SOC 2 compliance checks with detailed reporting
OWASP Top 10 Protection
Complete mitigation of all OWASP Top 10 security risks with defense-in-depth architecture
RBAC, middleware protection
AES-256, TLS 1.2+
Prisma ORM, DOMPurify
Security-first architecture
CSP, security headers
Regular updates, TypeScript
2FA, rate limiting, sessions
CSP, integrity checks
Audit logs, anonymization
URL validation, allowlists
Third-Party Validation
Passed
October 2025
Internal security audit completed with zero critical findings
Clean
0 critical findings
Last scanned: 10/11/2025