Trust
How we keep your systems safe, recoverable and yours
We follow widely accepted industry practice, and we are plain about what we do and do not claim. Where your data lives depends on where you operate. We scope that with you during the audit.
Standards we follow
We align our practices with recognized frameworks: the NIST Cybersecurity Framework, the CIS Critical Security Controls, and OWASP guidance for web applications. We do not claim certifications we do not hold, and we will complete your security questionnaire on request.
Security practices
- Encryption: data is encrypted in transit (TLS 1.2 or higher) and at rest.
- Access: multi-factor authentication on all administrative access, least-privilege permissions, and individual credentials instead of shared logins.
- Patching: security updates applied on a schedule, and critical patches applied promptly.
- Email authentication: SPF, DKIM and DMARC configured and monitored, so your mail reaches inboxes and cannot easily be spoofed.
- Monitoring: 24/7 uptime monitoring and alerting from Engine upward.
Backups and recovery
- Backups follow the 3-2-1 rule: three copies, on two kinds of storage, with one offsite.
- Backups run daily from Engine upward, and we restore on request.
- Ecosystem clients get scheduled restore tests, so a backup is proven before you need it.
Where your data lives
| United States | US regions by default |
| European Union | EU infrastructure, with a data processing agreement and GDPR-aligned handling |
| Gulf (UAE, KSA) | In-region hosting where your regulations call for it, scoped during the audit |
| Elsewhere | Agreed with you during the audit, based on your data requirements |
For clients in the European Union, we host on EU infrastructure and handle personal data in line with the GDPR. We sign a data processing agreement, keep your data within the EU, and provide a list of our sub-processors on request.
Ownership and exit
Your domain, accounts and data stay in your name at all times. If you leave, we hand over credentials and documentation within five business days, and we do not hold anything back.
If something goes wrong
Critical incidents are acknowledged within 4 hours on Engine and within 1 hour on Ecosystem. After every critical incident you receive a written summary of what happened, what we did and what changes as a result.
Contract terms
Identity and Engine are month-to-month with 30 days' notice. Ecosystem starts with a three-month term, then runs month-to-month.
Questions
Send us your security questionnaire or ask about data location through the free audit.