Trust and security

How we protect your network's sites and data.

Security is structural, not procedural. SectionOS runs networks of independently operated sites, so the controls that keep one location from affecting another are built into the platform, not left to policy. We build on SOC 2 Type II certified infrastructure and enforce tenant isolation at the database layer.

SOC 2 Type II infrastructure Row Level Security isolation AES-256 at rest MFA on every production account PIPEDA-aligned
Compliance status

What's in place, and what's next

Today

  • Built on SOC 2 Type II certified infrastructure providers
  • Tenant isolation enforced at the database layer with PostgreSQL Row Level Security
  • MFA required on every account with production access
  • AES-256 at rest, TLS 1.2 or higher in transit
  • Continuous vulnerability and secrets scanning across every repository
  • PIPEDA-aligned data handling, with a data processing agreement available on request
  • A written information security program covering access, incident response, and vendor management

On the roadmap

  • SOC 2 Type I, then Type II attestation
  • Independent third-party penetration testing, annually
  • SSO for hub and operator accounts
  • Public status page with historical uptime
Principles

A control you have to remember is a control that eventually fails.

One principle runs through every architecture decision. We build security in where it can't be bypassed, rather than relying on discipline to hold the line.

Protection

How your data is protected

Tenant isolation

Every site runs as its own tenant, isolated with PostgreSQL Row Level Security below the application layer. One location can never reach another's data or the hub's controls.

Encryption

AES-256 at rest across the database, backups, and object storage. TLS 1.2 or higher in transit.

Access

Granted by role, with MFA required on every account that has production access. Hub and location permissions are separate and don't overlap. Access is reviewed regularly and revoked on role change.

Infrastructure

Defined as code, running on SOC 2 Type II certified providers behind a global edge network with WAF, DDoS mitigation, and rate limiting. Environments are isolated, with automated backups.

Operations

Monitoring and incident response

Uptime and security events are monitored with automated on-call escalation, and every state-changing action is audit-logged. We keep a documented incident response playbook and disclose confirmed breaches to affected clients within 72 hours.

Privacy

The minimum data needed to run the platform

Handling is PIPEDA-aligned, with GDPR and CCPA principles reflected throughout, and cookie consent is opt-in with granular controls. Data requests go to trust@sectionos.io.

Sub-processors

A small footprint, fully disclosed

AWS Cloudflare Aikido Better Stack Sentry 1Password GitHub Loops.so Voiceflow Google Analytics Microsoft Clarity

Plus a cookie consent tool at launch. Each sub-processor is bound by an agreement appropriate to the data it handles. We keep this list current and notify contracted clients of material changes.

Responsible disclosure

Found a vulnerability? Tell us privately first.

Report it to security@sectionos.io. We acknowledge every good-faith report within five business days and keep you updated until it closes.

  • Please avoid scanning that degrades service
  • Please avoid accessing data that isn't yours
  • Please avoid public disclosure before a fix ships

Questions

Reviewing SectionOS? We answer security questionnaires and share our security overview under NDA. Email security@sectionos.io, we respond within one business day.

Security and disclosure security@sectionos.io
Privacy and data requests trust@sectionos.io