Skip to content
NativeLink

Security

Security you can audit, not just trust.

Our security program is aligned to the SOC 2 framework and covers our organization, our cloud infrastructure, access, and vendors. The controls below describe how we protect your data.

Certifications

Independently verified.

SOC 2 Type II

Complete

Independently audited against the AICPA Trust Services Criteria. Report available under NDA.

ISO 27001

Complete

Certified against the ISO/IEC 27001 information security management standard.

GDPR

Compliant

Data Processing Addendum available on request. Self-host for data residency.

CCPA / CPRA

Compliant

California residents can request access, deletion, and opt-out at any time.

Organizational security

How we run the program.

Information Security Program

We have an Information Security Program in place that is communicated throughout the organization. It follows the criteria set forth by the SOC 2 Framework, a widely known information security auditing procedure created by the American Institute of Certified Public Accountants.

Third-party audits

Our organization undergoes independent third-party assessments to test our security and compliance controls.

Third-party penetration testing

We perform independent third-party penetration testing at least annually to ensure that the security posture of our services is uncompromised.

Roles and responsibilities

Roles and responsibilities related to our Information Security Program and the protection of our customers' data are well defined and documented. Team members are required to review and accept all of the security policies.

Security awareness training

Our team members are required to complete security awareness training covering industry-standard practices and information security topics such as phishing and password management.

Confidentiality

All team members are required to sign and adhere to an industry-standard confidentiality agreement prior to their first day of work. Because many of our customers operate in security-focused and regulated environments, we take it a step further: confidentiality obligations continue after employment ends, access to customer data is strictly need-to-know, and we are glad to sign customer-specific NDAs on request.

Background checks

We perform background checks on all new team members in accordance with local laws.

Cloud security

Where your data lives, and how it's protected.

Cloud infrastructure security

Our services are hosted with Amazon Web Services (AWS), Google Cloud Platform (GCP), and Convex. They each run robust security programs with multiple certifications.

Data hosting security

Our data is hosted on AWS, GCP, and Convex, located in the United States. See the vendor documentation referenced under Cloud infrastructure security for more information.

Encryption at rest

All databases are encrypted at rest.

Encryption in transit

Our applications encrypt data in transit with TLS/SSL.

Vulnerability scanning

We perform vulnerability scanning and actively monitor for threats.

Logging and monitoring

We log activity across our AWS and GCP cloud infrastructure and monitor it for security and operational issues.

Business continuity and disaster recovery

We use our data hosting provider's backup services to reduce the risk of data loss in the event of a hardware failure, and monitoring services to alert the team to any failures affecting users.

Incident response

We have a process for handling information security events that includes escalation procedures, rapid mitigation, and communication.

Access security

Who can reach what.

Permissions and authentication

Access to cloud infrastructure and other sensitive tools is limited to authorized employees who require it for their role. Where available, we use Single Sign-On (SSO), two-factor authentication (2FA), and strong password policies to protect access to cloud services.

Least privilege access control

We follow the principle of least privilege with respect to identity and access management.

Quarterly access reviews

We perform quarterly access reviews of all team members with access to sensitive systems.

Password requirements

All team members are required to adhere to a minimum set of password requirements and complexity for access.

Password managers

All company-issued laptops use a password manager for team members to manage passwords and maintain complexity.

Vendor and risk management

Managing third parties and risk.

Annual risk assessments

We undergo at least annual risk assessments to identify potential threats, including considerations for fraud.

Vendor risk management

Vendor risk is determined and the appropriate vendor reviews are performed prior to authorizing a new vendor.

Contact us

Questions, or something to report?

If you have any questions, comments, or concerns, or wish to report a potential security issue, please contact us.

Ship faster

Let's build at the speed your code is being written.

Open source. Free cloud tier. Self-host the moment your team is ready.