Security & reliability
Security is part of how we engineer, not an afterthought we bolt on. This page is a plain-English summary of our security posture, our certifications, and how we respond when something goes wrong.
01Certifications
We maintain the following independent attestations. Reports are available under NDA to active and prospective clients.
- SOC 2 Type II — annual audit, latest period covers 2024
- ISO 27001 — certified information security management system
- GDPR — Article 28-compliant Data Processing Addendum available
- HIPAA — Business Associate Agreement available for healthcare engagements
02Data protection
All client data is encrypted at rest using AES-256 and in transit using TLS 1.3. Encryption keys are rotated annually and managed via the cloud provider's HSM-backed key management service. Production access is gated by hardware-key MFA and reviewed quarterly.
03Reliability
Our infrastructure runs multi-region with automated failover. We publish a public status page that you can subscribe to. Our internal SLO for client-facing services is 99.95% monthly uptime, measured externally and reviewed in monthly engineering retrospectives.
04Incident response
Every incident affecting client data triggers a runbook owned by our SRE team. Affected clients are notified within four hours of confirmation. A written postmortem with root cause and remediation timeline is provided within ten business days — and we publish a sanitized version on the engineering blog whenever the lesson generalizes.
05Responsible disclosure
If you've found a security issue, please email security@igknight.tech. We acknowledge reports within one business day, keep you in the loop on remediation, and credit responsible reporters in our public security log unless asked otherwise.
Questions about anything on this page? legal@igknight.tech — we read every message.
Talk to us