Security

Security at Somix

We take the security of your data seriously. Here is how we protect it at every layer.

Encryption

All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256. API keys and secrets are hashed using bcrypt and stored in isolated vaults.

Infrastructure

Our infrastructure runs in SOC 2 compliant data centers with 24/7 physical security, redundant power, and network isolation. We use Docker containerization with regular vulnerability scanning.

Monitoring & Incident Response

Continuous security monitoring, automated threat detection, and a dedicated incident response team available 24/7. Critical vulnerabilities are addressed within 24 hours.

Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities. Please report issues to [email protected]. We commit to acknowledging reports within 48 hours and resolving critical issues within 7 days.

Access Control

Role-based access control with principle of least privilege. All access is logged and audited. Multi-factor authentication is required for all production systems.

Compliance

We align with industry standards including SOC 2, GDPR, and Singapore's PDPA. Annual third-party penetration testing and security audits.

To report a security vulnerability, contact [email protected].
PGP key available upon request.