Security & Data Residency
Last updated: 2025-01-01
Security Overview
CEOTXT takes the security of your data seriously. This page describes our security practices and infrastructure.
Infrastructure Security
Hosting
- Hosted on SOC 2 Type II compliant infrastructure
- All servers run in isolated environments
- Automatic scaling and redundancy across multiple availability zones
Network Security
- TLS 1.3 encryption for all data in transit
- DDoS protection and rate limiting
- Web Application Firewall (WAF) protection
- Regular vulnerability scanning
Data Encryption
- AES-256 encryption for all data at rest
- Database encryption at the storage level
- Encrypted backups stored in geographically separate locations
Application Security
Authentication
- Secure session management
- Multi-factor authentication support
- OAuth 2.0 / OpenID Connect integration
- Password hashing with bcrypt
Authorization
- Role-based access control (Owner, Admin, Member)
- Workspace-level data isolation
- API rate limiting per user and workspace
Audit Logging
- Complete audit trail for all data modifications
- Correction mode with full history preservation
- Immutable audit logs for compliance
Data Residency
Primary Data Center
All customer data is stored in the United States. Our primary infrastructure runs in US-based data centers.Backups
- Automated daily backups
- Point-in-time recovery capability
- Backup data stored in encrypted, geographically separate locations
- 30-day backup retention
Data Isolation
Each workspace operates in a logically isolated environment. Data from one workspace is never accessible to users of another workspace.Compliance
- SOC 2 Type II compliant infrastructure
- GDPR-ready data handling practices
- Regular third-party security audits
- Vulnerability disclosure program
Incident Response
We maintain a documented incident response plan that includes:
- 24/7 monitoring and alerting
- Defined escalation procedures
- Customer notification within 72 hours of confirmed data breach
- Post-incident review and remediation
Responsible Disclosure
If you discover a security vulnerability, please report it to security@ceotxt.com. We appreciate responsible disclosure and will acknowledge your report within 48 hours.
