Trust, explained plainly
This page is a starting point for security reviews. For questionnaires, pen-test packages, or custom DPAs, contact us.
Cloud hosting
We run on major cloud providers with hardened baselines. Production workloads are isolated from development and demo environments.
Encryption and access
Data is encrypted in transit (TLS) and at rest. Role-based access ensures reviewers only see submissions they are assigned to handle.
Tenant isolation
Customer data is partitioned logically with strict scoping on every API path. We design for least privilege across services.
Backups and recovery
Databases are backed up on a recurring schedule with tested restore procedures. RPO/RTO targets are defined per environment tier.
Practices
We maintain change management for production systems, dependency scanning in CI, and logging for security-relevant events. Incident response playbooks include customer notification paths when warranted by policy or regulation.
Disclosures
Report suspected vulnerabilities to security@subplat.com (placeholder). Please avoid public disclosure until we have confirmed receipt and mitigation steps.
Read the Privacy Policy for how personal data is handled.