Platform security
- User information, app data, and logs are stored and maintained separately
- Passwords are encrypted
- Events are captured, monitored, and actioned in real time
- Infrastructure penetration testing done by industry-recognized third party
- File destruction begins at 30 days post project closure and meets NIST 800-88 guidelines
- Platform data secured in transit using TLS 1.2 encryption
- Data at rest secured with AES 256 encryption
- Vulnerability scans conducted regularly
- Cloudflare Web Application Firewall (WAF) monitors for malicious events
- Cloudflare DDOS protection detects and mitigates distributed denial-of-service attacks