Security
Last updated: August 18, 2026
Overview
At Artefae, security is a top priority. We implement comprehensive security measures to protect your data and ensure the confidentiality, integrity, and availability of our platform.
Infrastructure Security
Our platform is built on secure, enterprise-grade infrastructure:
- Cloud Hosting: Hosted on AWS with multi-region redundancy for high availability
- Encryption in Transit: TLS 1.2+ for all data transmission
- Encryption at Rest: AES-256 encryption for stored data
- DDoS Protection: Integrated DDoS mitigation and rate limiting
- Network Security: Firewalls, VPCs, and security groups for network isolation
Authentication & Authorization
We employ robust authentication and access control measures:
- Multi-Factor Authentication: Optional 2FA support for enhanced security
- JWT Tokens: Secure token-based authentication with short expiration times
- Role-Based Access Control: Granular permissions for workspace members (Admin, Editor, Viewer)
- Session Management: Secure session handling with automatic timeout
- API Tokens: Support for programmatic access with optional expiration and revocation
Data Protection
Your data is protected through multiple layers of security:
- Tenant Isolation: Strict data isolation between workspaces and organizations
- Data Backups: Automated daily backups with multi-region replication
- Access Logs: Comprehensive audit trail of all user actions
- Data Deletion: Secure, verified deletion of data upon request
- Compliance: GDPR, CCPA, and SOC 2 compliance measures
Application Security
We maintain rigorous application security practices:
- OWASP Top 10: Protection against common web vulnerabilities
- Input Validation: Strict validation and sanitization of all inputs
- CSRF Protection: Cross-site request forgery protection tokens
- SQL Injection Protection: Parameterized queries and ORM frameworks
- XSS Protection: Content Security Policy and output encoding
- Security Headers: Comprehensive HTTP security headers
Monitoring & Incident Response
We continuously monitor our systems and respond to security incidents:
- Real-time Monitoring: 24/7 security monitoring and alerting
- Intrusion Detection: IDS/IPS systems for threat detection
- Log Aggregation: Centralized logging and security event analysis
- Incident Response Plan: Documented procedures for security incident response
- Security Updates: Regular patching and vulnerability management
Testing & Auditing
Security testing is integral to our development process:
- Security Testing: Regular penetration testing and vulnerability assessments
- Code Review: Security-focused code reviews for all changes
- Dependency Scanning: Continuous monitoring of third-party dependencies
- SAST/DAST: Static and dynamic application security testing
- Third-party Audits: Regular security audits by external firms
Employee & Vendor Security
We maintain strict security practices for our team and vendors:
- Background checks for all employees with access to customer data
- Security training and awareness programs
- Confidentiality and non-disclosure agreements
- Vendor security assessments and contractual requirements
- Principle of least privilege for system access
Compliance Certifications
Artefae maintains the following security certifications and compliance standards:
- SOC 2 Type II (In Progress)
- GDPR Compliant
- CCPA Compliant
- ISO 27001 (Planned)
Responsible Disclosure
If you discover a security vulnerability, please report it responsibly to security@artefae.io. We appreciate the security research community and will work with you to address any issues promptly.
Please note:
- Do not publicly disclose the vulnerability until we have had time to address it
- Avoid accessing or modifying other users’ data
- Do not perform tests that could disrupt service to other users
- We will keep you updated on our progress and timeline for fixes
Contact Security Team
For security-related inquiries or to report vulnerabilities, please contact:
Email: security@artefae.io
GPG Key: [Available upon request]