How we protect your data and our infrastructure.
All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Database connections use SSL.
JWT tokens with bcrypt password hashing. Rate limiting on authentication endpoints. Session expiry after 2 hours.
All outbound scan requests are routed through anonymized proxy connections, protecting both our infrastructure and your targets.
Role-based access control for teams. Admin-only endpoints require elevated privileges. API rate limiting protects against abuse.
Hosted on enterprise-grade infrastructure with DDoS protection, WAF, and automated backups. Regular security patches applied.
Found a vulnerability? Contact [email protected]. We appreciate responsible disclosure and will respond within 48 hours.