Security

Security

Your security is our top priority. Learn about the comprehensive measures we implement to protect your data and maintain platform integrity.

Enterprise-Grade Security Last Updated: July 26, 2026
256-bit Encryption All data is encrypted in transit using TLS 1.2+ and at rest using AES-256-GCM encryption standards.
Secure Authentication Advanced authentication with strong password policies, session management, and brute-force protection.
Secure Infrastructure Hosted on enterprise-grade infrastructure with redundancy, monitoring, and DDoS protection.
Regulatory Compliance Designed to meet GDPR, UK GDPR, and PIPEDA requirements for data protection.

Data Encryption

We employ industry-leading encryption technologies to protect your data at every stage:

TLS 1.2+ Encryption All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher, with TLS 1.3 preferred.
AES-256 at Rest Sensitive fields (API keys, MFA secrets, PII) are encrypted with AES-256-GCM at the field level, on top of AES-256 storage-level encryption for data at rest.
Secure Key Management Encryption keys are securely managed and rotated regularly using industry best practices.
Password Hashing Passwords are hashed using Argon2id (with bcrypt as a fallback), never stored in plain text.

Authentication & Access Control

We implement multiple layers of authentication and access control to protect your account:

Password Security

Multi-Factor Authentication (MFA)

Session Security

Brute-Force Protection

Application Security

Our application is built with security-first principles and protected against common web vulnerabilities:

Security Headers

Content Security Policy (CSP) Prevents XSS attacks by controlling allowed content sources
X-Frame-Options: DENY Prevents clickjacking by blocking page embedding
HSTS Enforcement Forces HTTPS connections with preload support
X-Content-Type-Options Prevents MIME type sniffing attacks

Attack Prevention

Infrastructure Security

Our infrastructure is designed with defense in depth, providing multiple layers of protection:

Network Security

Server Security

Database Security

Compliance & Data Protection

Our security practices are designed to meet or exceed regulatory requirements across multiple jurisdictions:

GDPR Compliant EU General Data Protection Regulation
UK GDPR Compliant United Kingdom Data Protection
PIPEDA Compliant Canadian Privacy Legislation
PCI DSS Payment Card Industry Standards (via Stripe)

Data Protection Measures

Incident Response

We maintain comprehensive incident response procedures to quickly address any security issues:

Response Process

  1. Detection & Analysis: Automated monitoring and manual review identify potential incidents
  2. Containment: Immediate steps to limit impact and preserve evidence
  3. Eradication: Remove the threat and address root causes
  4. Recovery: Restore normal operations with enhanced safeguards
  5. Post-Incident Review: Document lessons learned and improve defenses

Breach Notification

In the event of a data breach affecting your personal information:

Security Best Practices for Users

Help us keep your account secure by following these recommendations:

Recommended Actions:

  • Use a strong, unique password (12+ characters with mixed case, numbers, symbols)
  • Never share your login credentials with others
  • Log out when using shared or public computers
  • Keep your browser and operating system updated
  • Be cautious of phishing emails claiming to be from us
  • Review your account activity regularly for unauthorized access
  • Use a password manager to generate and store strong passwords
  • Report any suspicious activity to our security team immediately

Responsible Disclosure

We value the security research community and welcome responsible disclosure of vulnerabilities:

Reporting Security Issues

If you discover a security vulnerability, please report it responsibly:

Our Commitment

Safe Harbor & Rules of Engagement

The points below are the rules of engagement and legal safe harbor for good-faith security researchers — not something we expect a malicious actor to honour, but the line that separates authorised research from an attack. If you act in good faith and stay within this scope, we authorise your testing, will not treat it as a breach of our terms, and will not pursue or support legal action against you. Step outside it and the safe harbor no longer applies.

To stay in scope and keep safe-harbor protection, please do not:

  • Access, modify, or delete data belonging to other users — test only with accounts you control
  • Run denial-of-service, volumetric, or load/stress attacks against our systems
  • Use social engineering, phishing, or physical attacks against our staff or facilities
  • Publicly disclose a vulnerability before we’ve confirmed it is resolved (coordinated disclosure)

Security Questions or Concerns?

Our security team is here to help. Contact us for any security-related inquiries.

security@confidion.com