Security
How we protect what you trust us with
A plain description of the controls we actually run — no certifications we have not earned.
Our practices
Encryption
Traffic to our services is encrypted in transit with TLS. Data at rest is stored on encrypted volumes managed by our infrastructure providers.
Access control
Production access is limited to personnel who need it to operate or support the service, protected by multi-factor authentication and reviewed periodically.
Backups
Databases are backed up on a regular schedule with encrypted, rotated snapshots. Restores are tested rather than assumed to work.
Tenant separation
Each customer's data is logically separated, and application-level authorisation checks run on every request that touches customer data.
Monitoring
Application and infrastructure logs are collected centrally with alerting on error rates, availability and anomalous access patterns.
Vendor management
We use established infrastructure providers and limit what each may do with customer data by contract. We do not sell customer data.
Reporting a vulnerability
If you believe you have found a security vulnerability in our services, tell us before you tell anyone else. Email dipa@pingtail.com with enough detail for us to reproduce it.
- We acknowledge reports within 2 working days.
- We will keep you updated while we investigate and fix.
- We will not pursue legal action against researchers who report in good faith, avoid privacy violations, and give us reasonable time to fix before disclosing.
- Please do not run automated scanning that degrades service for our customers, or access data belonging to anyone but yourself.
Incident response
If an incident affects your data, we will tell you what happened, what data was involved, what we have done about it, and what — if anything — you need to do. We aim to notify affected customers within 72 hours of confirming a breach, and we will notify the relevant authority where the law requires it.
Questions about security or compliance?
We are happy to answer specific questions from prospective customers, including about data residency and processing agreements.
Contact us