Last updated: January 2025

1. Our security posture

As a ThreatNova Security company, security is the foundation of everything we build. We maintain SOC 2 Type II and ISO 27001 certifications, undergo annual third-party penetration testing, and follow a zero-trust architecture across all our systems. Our security program is led by a dedicated CISO and reviewed quarterly by our board.

2. Compliance certifications

We maintain the following certifications and attestations: SOC 2 Type II (audited annually by an independent CPA firm), ISO 27001:2022 (certified by BSI), HIPAA-ready (Business Associate Agreements available for healthcare clients), GDPR compliant (with EU representatives in Ireland and Germany), and CCPA compliant. Compliance reports are available under NDA to qualified prospects.

3. Secure development lifecycle

Every project follows our secure SDLC: threat modeling during design, dependency scanning in CI, SAST and DAST on every PR, mandatory code review by a security-trained engineer, and pre-launch penetration testing. We use Snyk, Semgrep, Dependabot, and custom ThreatNova rules to catch vulnerabilities before they ship.

4. Infrastructure security

All production infrastructure runs in AWS, Azure, or GCP regions with multi-AZ redundancy. Access is granted via SSO with hardware MFA, time-boxed, and logged. Secrets are managed via AWS KMS, HashiCorp Vault, or cloud-native equivalents. We use mTLS for all internal service communication and OPA for policy enforcement.

5. Incident response

We maintain a 24/7 incident response capability with on-call rotations across three time zones. Incidents are classified by severity (SEV1-SEV4) with response time SLAs. We conduct quarterly incident response exercises and annual red team engagements. Customers are notified of incidents affecting their data within 72 hours, per GDPR Article 34.

6. Data encryption

All data is encrypted in transit using TLS 1.3 (minimum TLS 1.2). Data at rest is encrypted using AES-256 with customer-managed keys where supported. Database backups are encrypted with separate keys. We support customer-provided keys (BYOK) in AWS, Azure, and GCP for clients with strict key custody requirements.

7. Vulnerability disclosure

We welcome responsible disclosure of security vulnerabilities. Email security@infinitycodelabs.com with details. We respond within 48 hours, acknowledge valid reports, and credit researchers in our public hall of fame (with permission). We do not pursue legal action against good-faith researchers.

8. Contact

For security inquiries, SOC 2 reports, or vulnerability disclosures, email security@infinitycodelabs.com. For urgent production security incidents affecting a client system, call our 24/7 hotline at +1 (213) 555-0199 and select option 2.