Security
How DATAGRIS protects your infrastructure and data — because our business is security.
Infrastructure Security
DATAGRIS runs entirely on AWS infrastructure in the us-east-1 region. All servers are deployed in private VPCs with strict security group rules, no public inbound access except through our load balancers, and full network flow logging via VPC Flow Logs.
Encryption at Rest
All customer data is encrypted using AES-256. Database volumes use EBS encryption, backups are encrypted with AWS KMS, and scan artifacts use per-file encryption keys.
Encryption in Transit
All communications enforce TLS 1.3 with strong cipher suites. HSTS is enabled, and we maintain an A+ TLS rating. API endpoints are protected by AWS CloudFront with WAF.
Access Control
Multi-factor authentication (MFA) is enforced for all administrative access. IAM roles follow least-privilege principles. All access is logged and audited monthly.
Security Monitoring
24/7 monitoring with GuardDuty, CloudTrail, and custom anomaly detection. Alerts feed into our own SOC engine for real-time correlation and response.
Penetration Testing
DATAGRIS undergoes quarterly third-party penetration tests. Our platform is tested against OWASP Top-10, NIST SP 800-115, and PTES frameworks.
Backup & Recovery
Automated daily backups with 30-day retention. Cross-region disaster recovery with RTO of 4 hours and RPO of 1 hour. Tested quarterly.
Application Security
Our software development lifecycle incorporates security at every stage:
- SAST — Static analysis on every pull request (Bandit, Semgrep)
- DAST — Dynamic scanning of staging environments
- Dependency Scanning — Automated CVE checking for all dependencies (Dependabot, Snyk)
- Code Review — Every change requires at least one peer review
- Secrets Detection — git-secrets and pre-commit hooks prevent credential leakage
Data Isolation
Customer data is strictly isolated at the application layer. Each customer operates in a logically separated environment with:
- Row-level security policies in the database
- Per-customer encryption keys for stored scan results
- Ephemeral scan execution environments that are destroyed after each scan
- No cross-tenant data access paths
Vulnerability Disclosure Program
We maintain a responsible disclosure policy for security researchers. If you discover a vulnerability in DATAGRIS:
- Email details to [email protected]
- Do not publicly disclose until we have had 90 days to remediate
- Do not access or exfiltrate customer data beyond what is necessary to demonstrate the vulnerability
We commit to acknowledging your report within 24 hours and providing regular updates on remediation progress.
Responsible Disclosure Hall of Fame
We thank the following researchers for helping us improve our security:
No entries yet — be the first! Send your findings to [email protected].
Contact
Security Team: [email protected]
Vulnerability Disclosure: [email protected]
PGP Key Fingerprint: BC1A 2DEF 3GHI 4JKL 5MNO 6PQR 7STU 8VWX