Your incident investigation data is sensitive. We treat its protection as our highest priority.
TLS 1.3 in transit, AES-256 at rest. Your data is encrypted at every stage.
Role-based permissions. Only authorized team members access investigation data.
GDPR compliant with full data export, deletion, and audit capabilities.
All data transmitted between your browser and our servers is encrypted using the latest TLS 1.3 protocol.
All stored data, including investigation reports and attachments, is encrypted using AES-256 encryption.
Your data is backed up every 6 hours with 30-day retention. Backups are encrypted and stored in geographically separate locations.
Each customer's data is logically isolated. Your investigation data is never mixed with other organizations.
Define roles for administrators, investigators, reviewers, and viewers. Each role has specific permissions.
Enterprise plans include single sign-on integration with your identity provider (Okta, Azure AD, etc.).
Strong password requirements including minimum length, complexity, and protection against common passwords.
Automatic session timeouts, secure session handling, and the ability to view/revoke active sessions.
DDoS protection, WAF (Web Application Firewall), and edge caching via Cloudflare.
Certificates are automatically provisioned and renewed. No manual certificate management required.
Real-time error tracking and security monitoring with Sentry. Alerts on suspicious activity.
Dependencies and infrastructure are kept up to date with the latest security patches.
Full compliance with EU General Data Protection Regulation including data export, deletion, and access rights.
Export all your data in machine-readable format at any time. Full data portability.
Request complete deletion of your data. We honor all erasure requests within 30 days.
Complete audit trail of data access and modifications for compliance reporting.
Data Processing Agreements available for enterprise customers upon request.
Your investigation data is never used to train AI models. We use Anthropic's Claude API which has a zero data retention policy.
Only necessary data is sent to AI for analysis. PII can be anonymized before processing.
Enterprise customers can disable AI features entirely if required by policy.
Our team is happy to discuss our security practices in more detail.