Security & Trust

Built for the questions your security team asks first.

Independent audits, encryption everywhere, the documentation your procurement reviewer wants. We treat your team's data the way we treat our own.

SOC 2 Type II

Independently audited every year. Reports available under NDA — no sales call required.

End-to-end encryption

AES-256 at rest. TLS 1.3 in transit. Tenant data isolated at the database level.

GDPR & data residency

DPA available. Choose US, EU, or APAC residency at provisioning. Sub-processor list is public.

99.9% uptime SLA

Three nines, measured monthly. Service credits for any breach. No negotiation needed.

Infrastructure

TempoShift runs on AWS in geographically distributed availability zones. Every customer's data is logically separated at the database level, with row-level tenant filters enforced at the application boundary.

All traffic between our services is encrypted with mutual TLS. Customer-facing endpoints use TLS 1.3 with HSTS, modern cipher suites, and certificate pinning where supported.

Access controls

Employee access to production systems requires SSO with hardware-key MFA. Every action is logged and reviewed monthly. We follow a least-privilege model — engineers don't have standing access to customer data; they request time-bounded elevation that's reviewed and audited.

Customer-facing access controls include role-based permissions, SAML/OIDC SSO, SCIM provisioning, IP allow-listing, and a full audit log of every approval, edit, and admin action.

Vulnerability management

We run continuous dependency scanning, static analysis on every commit, dynamic application security testing on every release, and quarterly third-party penetration tests. Findings flow into a tracked queue with SLA-bound remediation: critical issues within 24 hours, high within 7 days.

Incident response

Customer-impacting incidents are communicated on our status page in real time. Post-incident reviews are shared with affected customers within 5 business days. Security incidents specifically are reported to affected tenants within 72 hours of discovery, in line with GDPR.

Compliance

  • SOC 2 Type II. Annual independent audit. Report available under NDA.
  • GDPR. DPA available for signature. Sub-processors documented at /sub-processors.
  • CCPA. California Consumer Privacy Act compliant. Data subject requests honoured within 30 days.
  • HIPAA. BAA available on the Enterprise plan for covered entities.

Reporting a vulnerability

If you believe you've found a security issue, email security@appsinclouds.com. We respond within one business day. We don't currently run a paid bug bounty, but we credit external researchers in our security acknowledgements.

Need a security review for procurement? We'll share our SOC 2 Type II report, SIG questionnaire response, penetration test summary, and DPA under NDA. Get in touch.