SECURITY

Security by default.

TLS 1.3. AES-256. Regional hosting. Documents auto-purged. OWASP Top 10 mitigations. Responsible disclosure program. What we do, and how to report a vulnerability.

Encryption

TLS 1.3 in transit. AES-256-GCM at rest. Keys managed via cloud KMS with rotation every 90 days.

Regional residency

India: GCP Mumbai. EU/EEA: GCP Belgium. Africa + ME: GCP Johannesburg. No cross-region transfer without customer instruction.

Document auto-purge

Default 24 hours after API response delivery. Optional 5-minute purge per API key. Enterprise: custom retention or zero-retention.

OWASP Top 10 mitigations

Every release tested against OWASP Top 10. Web Application Firewall (WAF) in front of all endpoints. Quarterly penetration tests.

Audit logging

All API calls logged. All admin actions logged. Logs retained per regulatory requirement (90 days default, 7 years for Enterprise).

Access controls

Role-based access in customer portal. Per-API-key scoping. Webhook signature validation. IP allowlisting for Enterprise.

Responsible disclosure program

If you discover a security vulnerability in any Abscode product, please report it to us privately so we can fix it. We commit to:

  • Acknowledge your report within 24 hours
  • Provide a status update within 5 business days
  • Credit you publicly (with your consent) once the fix is shipped
  • Offer a bug bounty for qualifying findings (program details on request)

Email: security@abscode.com. PGP key available on request. Do NOT publicly disclose until we've shipped a fix.

Certifications & alignments

Abscode is built to align with the following standards. Formal certifications are pursued as we scale.

  • ISO 27001, Information Security Management (alignment, certification in progress)
  • SOC 2 Type II, alignment with Trust Services Criteria (audit planned 2027)
  • DPDP Act 2023, India Data Protection (see DPDP)
  • POPIA, South Africa Protection of Personal Information Act
  • GDPR, EU General Data Protection Regulation (see GDPR & EU data protection)
  • OWASP ASVS Level 2, Application Security Verification Standard

Enterprise customers, formal audit support

Enterprise customers can request our SOC 2 Type I report, ISO 27001 SOA, recent penetration test summary, and vendor security questionnaire (SIG / CAIQ format). Contact enterprise@abscode.com.