Trust & Security
Threatstealth is a security-first company. This page documents our security posture, certifications, practices, and how to report a vulnerability.
Compliance Certifications
Current certification status. We eat our own cooking — the certifications shown here are tracked and evidenced on Threatstealth itself.
SOC 2 Type II
In AuditAll five Trust Services Criteria — Security, Availability, Confidentiality, Processing Integrity, Privacy — continuously monitored with automated evidence collection.
ISO 27001:2022
PursuingInformation Security Management System aligned to the 2022 standard. Risk register, SoA, and all 93 Annex A controls implemented and evidenced.
PCI DSS v4.0
Pursuing300+ sub-requirements continuously validated across the cardholder data environment. QSA-ready evidence package auto-generated.
Security Practices
Key technical controls in place for all Threatstealth-managed infrastructure and customer data.
Encryption at rest
All data at rest encrypted with AES-256-GCM. Database-level encryption across all PostgreSQL storage. Encryption keys managed separately from data stores.
Encryption in transit
All traffic encrypted with TLS 1.3. HSTS with a 2-year max-age, preload list submission, and HSTS includeSubDomains enforced across all endpoints.
Multi-factor authentication
MFA enforced for all operator accounts. TOTP (RFC 6238) and backup codes supported. Admin-level actions require step-up verification.
Role-based access control
Granular RBAC with super_admin, editor, and viewer roles. All API endpoints enforce server-side permission checks — UI gating alone is never relied upon.
Audit logging
Every create, update, and delete action is written to an immutable audit log with actor identity, timestamp, IP, and change diff. Logs are exported to SIEM.
Tenant isolation
Row-level security enforced at the database layer. Every query is scoped to the authenticated tenant. No shared mutable state between organisations.
Penetration Testing
Threatstealth undergoes an annual black-box and grey-box penetration test conducted by an independent security firm. Findings are remediated within 90 days.
Enterprise customers may request a summary of the latest pen test findings and remediation status under NDA. Contact security@threatstealth.com.
Semgrep SAST runs on every pull request. DAST scans against staging run on every deployment to main. Security findings block merge until resolved.
Vulnerability Disclosure
We maintain a responsible disclosure programme with a 72-hour acknowledgement SLA and a 90-day coordinated disclosure timeline. Safe harbor applies.
Data Subprocessors
We maintain a current list of all subprocessors who process customer data on our behalf. We notify customers of changes 30 days in advance.
View subprocessors list →