SOC 2 Type II
Independently audited every year. Reports available under NDA — no sales call required.
Independent audits, encryption everywhere, the documentation your procurement reviewer wants. We treat your team's data the way we treat our own.
Independently audited every year. Reports available under NDA — no sales call required.
AES-256 at rest. TLS 1.3 in transit. Tenant data isolated at the database level.
DPA available. Choose US, EU, or APAC residency at provisioning. Sub-processor list is public.
Three nines, measured monthly. Service credits for any breach. No negotiation needed.
TempoShift runs on AWS in geographically distributed availability zones. Every customer's data is logically separated at the database level, with row-level tenant filters enforced at the application boundary.
All traffic between our services is encrypted with mutual TLS. Customer-facing endpoints use TLS 1.3 with HSTS, modern cipher suites, and certificate pinning where supported.
Employee access to production systems requires SSO with hardware-key MFA. Every action is logged and reviewed monthly. We follow a least-privilege model — engineers don't have standing access to customer data; they request time-bounded elevation that's reviewed and audited.
Customer-facing access controls include role-based permissions, SAML/OIDC SSO, SCIM provisioning, IP allow-listing, and a full audit log of every approval, edit, and admin action.
We run continuous dependency scanning, static analysis on every commit, dynamic application security testing on every release, and quarterly third-party penetration tests. Findings flow into a tracked queue with SLA-bound remediation: critical issues within 24 hours, high within 7 days.
Customer-impacting incidents are communicated on our status page in real time. Post-incident reviews are shared with affected customers within 5 business days. Security incidents specifically are reported to affected tenants within 72 hours of discovery, in line with GDPR.
If you believe you've found a security issue, email security@appsinclouds.com. We respond within one business day. We don't currently run a paid bug bounty, but we credit external researchers in our security acknowledgements.