Security is structural, not procedural. SectionOS runs networks of independently operated sites, so the controls that keep one location from affecting another are built into the platform, not left to policy. We build on SOC 2 Type II certified infrastructure and enforce tenant isolation at the database layer.
One principle runs through every architecture decision. We build security in where it can't be bypassed, rather than relying on discipline to hold the line.
Every site runs as its own tenant, isolated with PostgreSQL Row Level Security below the application layer. One location can never reach another's data or the hub's controls.
AES-256 at rest across the database, backups, and object storage. TLS 1.2 or higher in transit.
Granted by role, with MFA required on every account that has production access. Hub and location permissions are separate and don't overlap. Access is reviewed regularly and revoked on role change.
Defined as code, running on SOC 2 Type II certified providers behind a global edge network with WAF, DDoS mitigation, and rate limiting. Environments are isolated, with automated backups.
Uptime and security events are monitored with automated on-call escalation, and every state-changing action is audit-logged. We keep a documented incident response playbook and disclose confirmed breaches to affected clients within 72 hours.
Handling is PIPEDA-aligned, with GDPR and CCPA principles reflected throughout, and cookie consent is opt-in with granular controls. Data requests go to trust@sectionos.io.
Plus a cookie consent tool at launch. Each sub-processor is bound by an agreement appropriate to the data it handles. We keep this list current and notify contracted clients of material changes.
Report it to security@sectionos.io. We acknowledge every good-faith report within five business days and keep you updated until it closes.
Reviewing SectionOS? We answer security questionnaires and share our security overview under NDA. Email security@sectionos.io, we respond within one business day.