Back to home

Security

Your data security is our top priority

256-bit
AES Encryption
TLS 1.3
Encryption in Transit
2FA
Account Protection
Daily
Automated Backups

Enterprise-Grade Security

End-to-End Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.

Isolated Infrastructure

Each tenant runs on dedicated infrastructure with complete data isolation.

Two-Factor Authentication

Protect your account with two-factor authentication and CAPTCHA-protected login.

Role-Based Access Control

Granular permissions ensure users only access data they need.

Activity Monitoring

Comprehensive logging and monitoring of all system activities.

Regular Backups

Automated daily backups with point-in-time recovery options.

Incident Response

Automated error tracking and uptime monitoring with a public status page.

Privacy by Design

GDPR data rights built in: export, deletion, consent management, and a signed DPA.

Data Protection

We implement multiple layers of security to protect your data at every stage.

Encryption

All data is encrypted using industry-standard AES-256 encryption at rest and TLS 1.3 in transit.

Infrastructure Isolation

Each tenant operates on isolated infrastructure with dedicated databases and complete data separation.

Secure Cloud Infrastructure

Hosted on hardened cloud infrastructure with automated security patches and updates.

Compliance

We build our data handling practices around major privacy regulations.

GDPR

Data protection

CCPA

California privacy

A note on certifications: We're an early-stage company and have not yet completed formal SOC 2 or ISO 27001 audits. When we do, we'll publish the reports here. In the meantime, we're happy to walk you through our security practices in detail.

Security Practices

Access Control

  • Two-factor authentication (2FA) available on all accounts
  • Role-based access control (RBAC) with granular permissions
  • Automatic session timeout after inactivity
  • Scoped, revocable API keys

Monitoring & Response

  • Automated error tracking and uptime monitoring
  • Rate limiting and abuse protection on all public endpoints
  • Comprehensive audit logging of all activities
  • Public status page at /status

Development & Testing

  • Security review as part of every code change
  • Automated dependency vulnerability scanning
  • Strict content security policy and security headers
  • Responsible disclosure process for security researchers

Responsible Disclosure

If you discover a security vulnerability, please report it to our security team immediately. We appreciate the security community's efforts in keeping SquirrelHQ secure.

Questions about our security?

Our team is happy to answer any questions about our security practices.

Get in touch