Trust & Security
How we handle your data, what we've attested to, and how to reach us for security questions.
Audit underway with a third-party assessor. Observation window started Q2 2026; target completion Q1 2027. Gap assessment complete; remediation in progress across all five Trust Services Criteria.
Data subject rights honored within 30 days. DPA available on request for customers with EU data subjects. EU data residency roadmap: Q4 2026.
California residents can request data export or deletion via privacy@securityalert.ai.
Standard DPA with SCCs signed on request for Business and Enterprise customers. Email legal@securityalert.ai.
Infrastructure
- Hosted on Microsoft Azure in the centralus region on hardened Ubuntu 24.04 LTS. Azure itself is SOC 2, ISO 27001, and HIPAA attested.
- PostgreSQL 16 with nightly backups (encrypted at rest on Azure managed disks) and per-tenant row-level isolation for multi-tenant data.
- TLS 1.3 enforced on all public endpoints. HSTS preloaded. Strict CAA policy restricting certificate issuance to Let's Encrypt.
- Nginx with rate limiting, IP blocklisting, and bot filtering on public endpoints.
- Secrets are stored in a protected environment file (0600, root-only read) outside the application directory. No credentials in source control.
Authentication & access
- Auth0 handles all customer authentication, RS256 signed JWTs with audience + issuer + expiry validation on every request.
- SSO (SAML/OIDC) on Enterprise plans, provisioned on request through Auth0 federated identity connections.
- API keys are generated via
random_bytes()and stored as bcrypt hashes. Keys are scoped per organisation and can be revoked instantly. - RBAC: team membership is enforced at the query layer, teams cannot read each other's monitors, incidents, or brand findings.
- Audit logs for privileged actions are retained for the lifetime of the subscription and exportable for SOC 2 preparation (Business tier and above).
Data handling
- What we collect: monitor configurations, incident and finding records, domains and assets you ask us to monitor, alert preferences, authorized directory context and account-level evidence you import, and the results of the checks you run. We do not sell data.
- What we don't collect: we do not proxy your application traffic or deploy agents inside your infrastructure. Identity ingestion rejects passwords, cookies, tokens, session data, raw authentication logs, and provider credentials. Read-only inventory and repository evidence enters only through workflows you configure or supply.
- Retention: retention periods and deletion behavior are documented on the public data-retention page. Audit events are retained for the lifetime of the subscription.
- Deletion: account deletion removes all tenant data immediately. Backups use a rolling 30-day retention setting and expired copies are removed during the next successful backup rotation.
- No PII in logs: HTTP logs are scrubbed of query strings and body content before rotation.
- AI agent access: the API and MCP endpoint expose read-only, tenant-scoped data to tools you connect. Credentials are Business-plan gated, rate limited, carry your role's permissions and nothing more, and every tool call lands in your audit log. There is no agent-reachable action that files or changes anything: a person approves outward actions, always.
Vulnerability disclosure
We welcome responsible disclosure. Report vulnerabilities to security@securityalert.ai. We commit to acknowledging reports within 48 hours and a public advisory after remediation. Safe-harbour extended to good-faith research that avoids customer data access and does not degrade service.
Our security.txt is published at /.well-known/security.txt.
Incident transparency
We publish our own operational status at status.securityalert.ai and run a public changelog for all product changes. Security-relevant incidents affecting customer data are disclosed to affected customers within 72 hours.
Subprocessors
- Microsoft Azure, infrastructure hosting (centralus)
- Auth0 / Okta, authentication
- Stripe, billing
- Postmark, transactional email
- Twilio, SMS alerts
- Cloudflare, DNS and DDoS protection
Full subprocessor list with purpose, data categories, and locations available in the DPA. Material changes notified to customers 30 days in advance.
Questions
Security questionnaires, SOC 2 bridge letters (post-attestation), penetration test summaries, and architecture diagrams available under NDA. Email security@securityalert.ai.
Last updated: 19 August 2026