Security & compliance

Built like a bank.
Feels like consumer.

Enterprise-grade by default — every customer, every plan. Not a paid add-on.

99.99%

Uptime SLA

< 50ms

Median API latency

24à—7

Security ops center

0

Reportable breaches

Certifications

Audited. Certified. Verified.

We've done the heavy lifting so your procurement team doesn't have to.

🛡

SOC 2 Type II

Annual independent audit

🛡

ISO 27001

Information security mgmt

🛡

GDPR

EU data protection compliant

🛡

HIPAA

Healthcare-grade controls

🛡

PCI-DSS

Card data handling

🛡

DPDP Act

India data protection

The four pillars

How we protect your data.

Encryption everywhere

AES-256 at rest. TLS 1.3 in transit. Per-tenant keys with optional BYOK (bring-your-own-key) for enterprise.

  • AES-256-GCM at rest
  • TLS 1.3 in transit
  • Per-tenant key isolation
  • AWS KMS / HSM-backed

Identity & access

Granular RBAC with field-level controls. SSO, SAML 2.0, SCIM provisioning, MFA enforceable org-wide.

  • Role + attribute-based access
  • SSO via SAML 2.0 / OIDC
  • SCIM auto-provisioning
  • MFA + biometric

Audit & observability

Immutable audit logs across every action. Webhooks to your SIEM. Real-time anomaly detection.

  • Immutable audit trail
  • SIEM webhooks (Splunk, Datadog)
  • Anomaly detection
  • Data retention controls

Data residency

Choose where your data lives. Multi-region deployments with strict data isolation.

  • US, EU, India, APAC regions
  • No cross-region replication
  • Data export anytime
  • Right-to-be-forgotten
Architecture

Defense in depth.

Every layer hardened, every layer monitored.

EdgeCloudflare WAF · DDoS protection · Bot mitigation
ApplicationOWASP Top 10 hardened · Per-tenant isolation · Rate limiting
DataAES-256 at rest · TLS 1.3 · BYOK · Field-level encryption
InfrastructureAWS multi-AZ · Private VPC · Zero-trust networking
PeopleBackground-checked · Annual training · Least-privilege access

Trust Center

Live status, security posture, current certifications.

Visit trust center

Security Whitepaper

30-page deep dive on architecture, controls, and processes.

Download PDF

Vulnerability Disclosure

Report a vulnerability via our coordinated disclosure program.

Report → security@

Procurement got questions?

Our security team responds within one business day.

▶ Live DemoBook Demo →