Enterprise-Grade Security

Security & Compliance

We take security seriously. Your data and privacy are protected by industry-leading security measures and compliance standards.

How We Protect Your Data

Data Encryption

All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3.

Secure Storage

Your scan data and credentials are stored in secure, isolated database instances with automatic backups.

Access Controls

Role-based access control (RBAC) ensures users only access resources they are authorized to see.

Authentication

Multi-factor authentication (MFA) and SSO support for enterprise customers.

Infrastructure Security

Hosted on enterprise-grade cloud infrastructure with 24/7 monitoring and automated security updates.

Vulnerability Management

Regular security audits and penetration testing of our own platform to ensure maximum security.

Compliance & Standards

Data Privacy

  • POPIA compliant (South Africa)
  • GDPR ready for European customers
  • Data residency options available
  • Right to deletion and data portability

Security Standards

  • OWASP Top 10 protected
  • Regular security assessments
  • Penetration testing program
  • Vulnerability disclosure program

Business Continuity

  • 99.9% uptime SLA
  • Automated daily backups
  • Disaster recovery plan
  • Business continuity procedures

Our Security Practices

Secure Development Lifecycle

Our development process follows security best practices including code reviews, automated security testing, and regular security audits. All code changes undergo thorough security review before deployment.

Credential Management

Credentials used for authenticated scanning are encrypted at rest and never logged. They are only used during active scans and are never exposed in reports or APIs.

Network Security

All scan traffic originates from dedicated IP addresses that can be whitelisted. Network isolation ensures scan containers cannot access internal infrastructure.

Incident Response

We have a comprehensive incident response plan with 24/7 monitoring. In the unlikely event of a security incident, affected customers will be notified within 72 hours.

Questions about our security?

Contact our security team for more information about our security practices and compliance.

Contact Security Team