Security

Last updated: August 18, 2026

Overview

At Artefae, security is a top priority. We implement comprehensive security measures to protect your data and ensure the confidentiality, integrity, and availability of our platform.

Infrastructure Security

Our platform is built on secure, enterprise-grade infrastructure:

  • Cloud Hosting: Hosted on AWS with multi-region redundancy for high availability
  • Encryption in Transit: TLS 1.2+ for all data transmission
  • Encryption at Rest: AES-256 encryption for stored data
  • DDoS Protection: Integrated DDoS mitigation and rate limiting
  • Network Security: Firewalls, VPCs, and security groups for network isolation

Authentication & Authorization

We employ robust authentication and access control measures:

  • Multi-Factor Authentication: Optional 2FA support for enhanced security
  • JWT Tokens: Secure token-based authentication with short expiration times
  • Role-Based Access Control: Granular permissions for workspace members (Admin, Editor, Viewer)
  • Session Management: Secure session handling with automatic timeout
  • API Tokens: Support for programmatic access with optional expiration and revocation

Data Protection

Your data is protected through multiple layers of security:

  • Tenant Isolation: Strict data isolation between workspaces and organizations
  • Data Backups: Automated daily backups with multi-region replication
  • Access Logs: Comprehensive audit trail of all user actions
  • Data Deletion: Secure, verified deletion of data upon request
  • Compliance: GDPR, CCPA, and SOC 2 compliance measures

Application Security

We maintain rigorous application security practices:

  • OWASP Top 10: Protection against common web vulnerabilities
  • Input Validation: Strict validation and sanitization of all inputs
  • CSRF Protection: Cross-site request forgery protection tokens
  • SQL Injection Protection: Parameterized queries and ORM frameworks
  • XSS Protection: Content Security Policy and output encoding
  • Security Headers: Comprehensive HTTP security headers

Monitoring & Incident Response

We continuously monitor our systems and respond to security incidents:

  • Real-time Monitoring: 24/7 security monitoring and alerting
  • Intrusion Detection: IDS/IPS systems for threat detection
  • Log Aggregation: Centralized logging and security event analysis
  • Incident Response Plan: Documented procedures for security incident response
  • Security Updates: Regular patching and vulnerability management

Testing & Auditing

Security testing is integral to our development process:

  • Security Testing: Regular penetration testing and vulnerability assessments
  • Code Review: Security-focused code reviews for all changes
  • Dependency Scanning: Continuous monitoring of third-party dependencies
  • SAST/DAST: Static and dynamic application security testing
  • Third-party Audits: Regular security audits by external firms

Employee & Vendor Security

We maintain strict security practices for our team and vendors:

  • Background checks for all employees with access to customer data
  • Security training and awareness programs
  • Confidentiality and non-disclosure agreements
  • Vendor security assessments and contractual requirements
  • Principle of least privilege for system access

Compliance Certifications

Artefae maintains the following security certifications and compliance standards:

  • SOC 2 Type II (In Progress)
  • GDPR Compliant
  • CCPA Compliant
  • ISO 27001 (Planned)

Responsible Disclosure

If you discover a security vulnerability, please report it responsibly to security@artefae.io. We appreciate the security research community and will work with you to address any issues promptly.

Please note:

  • Do not publicly disclose the vulnerability until we have had time to address it
  • Avoid accessing or modifying other users’ data
  • Do not perform tests that could disrupt service to other users
  • We will keep you updated on our progress and timeline for fixes

Contact Security Team

For security-related inquiries or to report vulnerabilities, please contact:

Email: security@artefae.io
GPG Key: [Available upon request]