Certifications
- SOC 2 Type II — audited annually by an independent CPA firm
- ISO 27001 — certification in progress (expected Q3 2025)
Encryption
- In transit: TLS 1.2 or higher for all connections
- At rest: AES-256 for all data stored in our production databases and object storage
- Key management: AWS KMS with automated key rotation
Access controls
- Least privilege — engineers only have access to the systems they need
- MFA required on all internal accounts
- SSO available on all customer plans; SAML/SCIM on Enterprise
- Audit logs for every administrative action, retained for 12 months
Reliability
- 99.9% uptime SLA on all plans (99.95% on Enterprise)
- Backups every hour, 35-day retention
- Disaster recovery tested quarterly with 4-hour RTO / 1-hour RPO
Incident response
Security incidents are triaged within 30 minutes. Customers affected by a confirmed breach are notified within 72 hours per GDPR Article 33.
Report a vulnerability: security@radius.ai