SASSYFOLIO

Trust

Security is a first-class feature.

We build SASSYFOLIO the way we'd want our own portfolio hosted — encrypted by default, audited continuously, and transparent about exactly what we store and why.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest. Secrets are stored in an isolated KMS-backed vault and rotated regularly.

PCI-DSS payment isolation

We never touch raw card or wallet credentials. Payments are tokenised by Stripe, PayPal, bKash, Nagad, Rocket, and SSLCommerz — all PCI-DSS Level 1 certified.

Authentication you control

Email + password, Google SSO, magic links, and TOTP two-factor authentication. Enterprise customers can enforce SAML SSO and SCIM provisioning.

SOC 2 Type II infrastructure

Hosted on SOC 2 Type II certified providers (AWS, Cloudflare). Daily encrypted backups with point-in-time recovery up to 7 days.

GDPR & DPA ready

Standard Contractual Clauses, signed Data Processing Agreements on request, and a documented data-subject access workflow for every region we serve.

Least-privilege access

Production access requires hardware key 2FA and is logged immutably. Engineers cannot view customer content without an explicit, audited support request.

Responsible disclosure

Found a vulnerability? We respond to every report within 48 hours and credit researchers in our public security acknowledgements once a fix has shipped.

Email security@sassyfolio.com — PGP key available on request.

Sub-processors

We use a short, audited list of sub-processors: AWS (hosting), Cloudflare (edge & DNS), Stripe, PayPal, SSLCommerz, bKash, Nagad, Rocket (payments), Resend (email). The full list with regions is in our DPA.