Hosting
All customer data is hosted in AWS Asia Pacific (Sydney) Region (ap-southeast-2).
Encryption
TLS 1.2+ in transit; AES-256 at rest; per-tenant encryption keys via AWS KMS.
Access control
Role-based access, single sign-on with enforced MFA, least-privilege provisioning, JIT engineering access with full audit.
Programme
SOC 2 Type II programme in progress with a Big-4 firm. ISO 27001 mapping complete.
Logging
Centralised, immutable audit logs retained for 13 months with tenant isolation.
Vulnerability management
Continuous SAST/DAST/SCA, monthly internal penetration testing, annual third-party red-team.
Incident response
24x7 on-call. Customer notification within 72 hours of confirmed material incident, consistent with Notifiable Data Breaches scheme.
Contact
security@spectraiq.ai
