独立认证。
ISO 27001:2022
SecureBlock's information security management system is certified against ISO 27001. Certificate available on request.
SOC 2 Type II
Annual SOC 2 Type II report covering security, availability, and confidentiality trust services criteria.
GDPR
Full GDPR compliance programme with published DPA available before commercial engagement.
我们实际的做法。
Data encryption
All customer data encrypted in transit (TLS 1.3) and at rest (AES-256). Per-tenant KMS keys with automatic rotation every 90 days.
Access control
Least-privilege model with SSO-required access, MFA on all human accounts, and just-in-time elevation for privileged operations with full audit logging.
Data lifecycle
Engagement data isolated per tenant, deleted 90 days after the retest window closes unless the customer requests earlier deletion or extended retention.
发现了什么?告诉我们。
我们为 SecureBlock 平台中的漏洞运行正式的披露计划。范围内的报告将在 24 小时内得到确认,并按照与严重性匹配的时间表进行修复。
- 在范围内: app.secureblock.io、api.secureblock.io 和 secureblock.io。
- 范围外: 客户租户(受其自身参与规则约束)、第三方服务、拒绝服务攻击以及对员工的社会工程学攻击。
- SLA: 初始确认在 24 小时内。关键修复在 7 天内。高危在 30 天内。其他尽力而为。
感谢帮助我们的研究人员。
想出现在这个列表上?请参阅上面的披露政策。
