Security
A plain description of the controls we run. Where a product makes a stronger commitment, its own security page says so.
Infrastructure
All products sit behind Cloudflare for DNS, TLS termination, web application firewall and DDoS protection. Application origins are not reachable except through it. Production, staging and development environments are separate, with separate credentials.
Encryption
Traffic is encrypted in transit with TLS 1.2 or higher. Data at rest is encrypted at the storage layer for databases, object storage and backups. Secrets are held in the platform's secret store, never in source code or configuration files.
Access
Access to production systems is limited to the engineers who operate the product in question, uses individual accounts with hardware-backed multi-factor authentication, and is reviewed when people join or leave. Customer data is accessed for support only with a reason recorded.
Backups and recovery
Databases are backed up continuously with point-in-time recovery, and snapshots are retained for at least thirty days. Object storage is versioned. Restores are tested when infrastructure changes and at least twice a year.
Application security
Dependencies are updated on a schedule and on advisories. Authentication uses well-tested libraries, with rate limiting on credential endpoints. Webhooks we send are signed; webhooks we receive are verified. Signed documents produced by AiroSign carry a PKCS#7 seal and an append-only audit trail so that tampering is detectable independently of us.
Incidents
We keep an incident process with a named lead, a timeline and a written post-incident review. Customers affected by a data incident are notified without undue delay and within any period the law requires.
Compliance
We do not currently hold a SOC 2 or ISO 27001 certification. The controls above are what we run; we will say so plainly rather than imply an audit that has not happened. Messaging products operate under carrier registration requirements in the United States and Canada; signing products are built to ESIGN, UETA and eIDAS requirements for simple electronic signatures.
Reporting a vulnerability
Email info@airosofts.com with the subject "Security". Include steps to reproduce. We acknowledge within two business days and will not pursue good-faith research that respects user data and service availability.