Security Policy
Last updated: August 29, 2026
Security is core to what AuditGate does, both for our own infrastructure and for the customer traffic that flows through our platform. This page describes the practices we follow to protect your data. If you've found a vulnerability, please see our Responsible Disclosure Policy.
1. Infrastructure Security
AuditGate is hosted on reputable cloud infrastructure providers. Data is encrypted in transit using TLS and encrypted at rest. Production environments are network-isolated from development and staging environments.
2. Access Control
Access to production systems and customer data is restricted to personnel who need it to operate the Service, following the principle of least privilege. Where available, we require multi-factor authentication for access to critical systems, and we log administrative access for audit purposes.
3. Application & Data Isolation
Customer data, including scan findings and API traffic metadata, is logically separated by account. Deleting a project removes the findings and reports associated with it, as described in our Privacy Policy.
4. Secure Development
As a security product ourselves, we hold our own software to the same standard we hold our customers' APIs to: code review before merge, dependency and vulnerability scanning in our build pipeline, and staged rollouts for changes to production.
5. Vulnerability Management
We continuously monitor dependencies and infrastructure for known vulnerabilities and patch critical issues on an expedited basis. We also welcome reports from external researchers through our Responsible Disclosure Policy.
6. Incident Response
We maintain an internal process for triaging, investigating, and responding to security incidents. Where an incident affects customer data, we will notify affected customers without undue delay and in accordance with applicable law.
7. Compliance Roadmap
AuditGate is an early-stage company. We are building our controls and reporting toward common frameworks referenced by our customers, such as SOC 2 and PCI-DSS control areas, and we will update this page as formal certifications are achieved. Current compliance reporting features reflect control-area mapping, not third-party audit certification, unless stated otherwise.
8. Subprocessors
We use a small number of infrastructure and tooling subprocessors (for example, cloud hosting and email delivery) to operate the Service. All subprocessors are bound by confidentiality and security obligations appropriate to the data they process. A current list is available on request.
9. Questions
For security questions, or to report a vulnerability, contact [email protected] or see our Responsible Disclosure Policy.


