Security & Data Residency

Last updated: 2025-01-01

Security Overview

CEOTXT takes the security of your data seriously. This page describes our security practices and infrastructure.

Infrastructure Security

Hosting

  • Hosted on SOC 2 Type II compliant infrastructure
  • All servers run in isolated environments
  • Automatic scaling and redundancy across multiple availability zones

Network Security

  • TLS 1.3 encryption for all data in transit
  • DDoS protection and rate limiting
  • Web Application Firewall (WAF) protection
  • Regular vulnerability scanning

Data Encryption

  • AES-256 encryption for all data at rest
  • Database encryption at the storage level
  • Encrypted backups stored in geographically separate locations

Application Security

Authentication

  • Secure session management
  • Multi-factor authentication support
  • OAuth 2.0 / OpenID Connect integration
  • Password hashing with bcrypt

Authorization

  • Role-based access control (Owner, Admin, Member)
  • Workspace-level data isolation
  • API rate limiting per user and workspace

Audit Logging

  • Complete audit trail for all data modifications
  • Correction mode with full history preservation
  • Immutable audit logs for compliance

Data Residency

Primary Data Center

All customer data is stored in the United States. Our primary infrastructure runs in US-based data centers.

Backups

  • Automated daily backups
  • Point-in-time recovery capability
  • Backup data stored in encrypted, geographically separate locations
  • 30-day backup retention

Data Isolation

Each workspace operates in a logically isolated environment. Data from one workspace is never accessible to users of another workspace.

Compliance

  • SOC 2 Type II compliant infrastructure
  • GDPR-ready data handling practices
  • Regular third-party security audits
  • Vulnerability disclosure program

Incident Response

We maintain a documented incident response plan that includes:

  • 24/7 monitoring and alerting
  • Defined escalation procedures
  • Customer notification within 72 hours of confirmed data breach
  • Post-incident review and remediation

Responsible Disclosure

If you discover a security vulnerability, please report it to security@ceotxt.com. We appreciate responsible disclosure and will acknowledge your report within 48 hours.