Security

Our commitment to security

We take the security of your data as seriously as you do. Here's how we protect it at every layer.

Our security posture

Security is foundational to everything we build at Secure Raven. As a security compliance platform, we hold ourselves to the highest standards — the same standards our agents help you achieve. Our infrastructure, processes, and people are continuously assessed against industry-leading frameworks.

We employ defense-in-depth across every layer of our stack: from network perimeter hardening and runtime application security to employee background checks and mandatory security awareness training. Every production change goes through automated security scanning, code review, and staged rollouts.

Transparency is core to our approach. We maintain a public security page, promptly disclose any incidents, and welcome responsible security research from the community. We believe trust is earned through action, not marketing.

SOC 2 Type II in progress

AES-256-GCM credentials

TLS in transit + HSTS

Automated security scans

Data Protection

How we protect your data

Multiple layers of security controls work together to keep your data safe at every stage.

Encryption at Rest

Customer database credentials are envelope-encrypted with AES-256-GCM and per-tenant keys. Other platform data is encrypted at rest by our cloud providers. We do not yet encrypt every findings or events column at the application layer.

Encryption in Transit

Dashboard and API traffic is served over HTTPS. We send HSTS on every response. We do not currently implement browser certificate pinning.

Access Controls

Role-based access (viewer, member, admin) is enforced in the database with RLS. Multi-factor authentication is available through Supabase Auth but is not yet mandatory for admins.

Infrastructure Security

Hosted on SOC 2 compliant cloud infrastructure with network segmentation and private subnets. Platform WAF rules are a hosting control, not a customer Shield adapter.

Vulnerability Management

Every PR runs npm audit, Semgrep, and gitleaks. External penetration testing is on the roadmap; it is not a completed annual program yet.

Incident Response

We publish a written incident-response policy with severity levels and disclosure clocks. On-call rotation and 24/7 monitoring are not fully staffed yet.

Certifications

Certifications & compliance

What we have implemented versus what we have not certified. We will not claim an audit we have not completed.

SOC 2 Type II

Control map and policies exist. Secure Raven is not independently audited for SOC 2 Type II yet. Our cloud providers are.

In progress

HIPAA Hawk

Technical safeguard checks plus a vendor BAA inventory. Not a HIPAA certification and not a substitute for legal BAAs.

In product

ISO 27001

Control catalog mapped for gap detection. Secure Raven is not ISO 27001 certified.

Mapped

GDPR

Control mapping and tenant isolation patterns. Not a GDPR certification.

Mapped
Disclosure

Responsible disclosure

We welcome security researchers and are committed to working with the community.

Responsible Disclosure

We take security vulnerabilities seriously and appreciate the work of researchers who help us improve. If you’ve discovered a potential security issue in Secure Raven, we encourage you to report it through our responsible disclosure program.

Please send details of the vulnerability, including reproduction steps, to:

security@secureraven.com

We commit to responding within 24 hours and will work with you to understand and resolve the issue promptly. We will not pursue legal action against researchers acting in good faith.

See also our vulnerability disclosure policy. A PGP key will be published here when one is issued.

Questions about our security?

Our security team is happy to answer questions, provide documentation, or walk through our practices.