Security by default.
TLS 1.3. AES-256. Regional hosting. Documents auto-purged. OWASP Top 10 mitigations. Responsible disclosure program. What we do, and how to report a vulnerability.
Encryption
TLS 1.3 in transit. AES-256-GCM at rest. Keys managed via cloud KMS with rotation every 90 days.
Regional residency
India: GCP Mumbai. EU/EEA: GCP Belgium. Africa + ME: GCP Johannesburg. No cross-region transfer without customer instruction.
Document auto-purge
Default 24 hours after API response delivery. Optional 5-minute purge per API key. Enterprise: custom retention or zero-retention.
OWASP Top 10 mitigations
Every release tested against OWASP Top 10. Web Application Firewall (WAF) in front of all endpoints. Quarterly penetration tests.
Audit logging
All API calls logged. All admin actions logged. Logs retained per regulatory requirement (90 days default, 7 years for Enterprise).
Access controls
Role-based access in customer portal. Per-API-key scoping. Webhook signature validation. IP allowlisting for Enterprise.
Responsible disclosure program
If you discover a security vulnerability in any Abscode product, please report it to us privately so we can fix it. We commit to:
- Acknowledge your report within 24 hours
- Provide a status update within 5 business days
- Credit you publicly (with your consent) once the fix is shipped
- Offer a bug bounty for qualifying findings (program details on request)
Email: security@abscode.com. PGP key available on request. Do NOT publicly disclose until we've shipped a fix.
Certifications & alignments
Abscode is built to align with the following standards. Formal certifications are pursued as we scale.
- ISO 27001, Information Security Management (alignment, certification in progress)
- SOC 2 Type II, alignment with Trust Services Criteria (audit planned 2027)
- DPDP Act 2023, India Data Protection (see DPDP)
- POPIA, South Africa Protection of Personal Information Act
- GDPR, EU General Data Protection Regulation (see GDPR & EU data protection)
- OWASP ASVS Level 2, Application Security Verification Standard
Enterprise customers, formal audit support
Enterprise customers can request our SOC 2 Type I report, ISO 27001 SOA, recent penetration test summary, and vendor security questionnaire (SIG / CAIQ format). Contact enterprise@abscode.com.