Enterprise-Grade Security

Security at InvestigatePro

Your incident investigation data is sensitive. We treat its protection as our highest priority.

Encryption

TLS 1.3 in transit, AES-256 at rest. Your data is encrypted at every stage.

Access Control

Role-based permissions. Only authorized team members access investigation data.

Compliance Ready

GDPR compliant with full data export, deletion, and audit capabilities.

Our Security Practices

Data Protection

TLS 1.3 Encryption

All data transmitted between your browser and our servers is encrypted using the latest TLS 1.3 protocol.

AES-256 Encryption at Rest

All stored data, including investigation reports and attachments, is encrypted using AES-256 encryption.

Automated Backups

Your data is backed up every 6 hours with 30-day retention. Backups are encrypted and stored in geographically separate locations.

Data Isolation

Each customer's data is logically isolated. Your investigation data is never mixed with other organizations.

Access Control

Role-Based Access Control (RBAC)

Define roles for administrators, investigators, reviewers, and viewers. Each role has specific permissions.

SSO/SAML Integration (Enterprise)

Enterprise plans include single sign-on integration with your identity provider (Okta, Azure AD, etc.).

Secure Password Requirements

Strong password requirements including minimum length, complexity, and protection against common passwords.

Session Management

Automatic session timeouts, secure session handling, and the ability to view/revoke active sessions.

Infrastructure Security

Cloudflare Protection

DDoS protection, WAF (Web Application Firewall), and edge caching via Cloudflare.

Automatic SSL/TLS Certificates

Certificates are automatically provisioned and renewed. No manual certificate management required.

Security Monitoring

Real-time error tracking and security monitoring with Sentry. Alerts on suspicious activity.

Regular Updates

Dependencies and infrastructure are kept up to date with the latest security patches.

Compliance

GDPR Compliant

Full compliance with EU General Data Protection Regulation including data export, deletion, and access rights.

Data Export (Article 20)

Export all your data in machine-readable format at any time. Full data portability.

Right to Erasure (Article 17)

Request complete deletion of your data. We honor all erasure requests within 30 days.

Audit Logging

Complete audit trail of data access and modifications for compliance reporting.

DPA Available (Enterprise)

Data Processing Agreements available for enterprise customers upon request.

AI Security & Privacy

No AI Training on Your Data

Your investigation data is never used to train AI models. We use Anthropic's Claude API which has a zero data retention policy.

Data Minimization

Only necessary data is sent to AI for analysis. PII can be anonymized before processing.

AI Disable Option

Enterprise customers can disable AI features entirely if required by policy.

Questions About Security?

Our team is happy to discuss our security practices in more detail.