Encryption everywhere
TLS 1.3 in transit, AES-256 at rest. Secrets are stored in an isolated KMS-backed vault and rotated regularly.
PCI-DSS payment isolation
We never touch raw card or wallet credentials. Payments are tokenised by Stripe, PayPal, bKash, Nagad, Rocket, and SSLCommerz — all PCI-DSS Level 1 certified.
Authentication you control
Email + password, Google SSO, magic links, and TOTP two-factor authentication. Enterprise customers can enforce SAML SSO and SCIM provisioning.
SOC 2 Type II infrastructure
Hosted on SOC 2 Type II certified providers (AWS, Cloudflare). Daily encrypted backups with point-in-time recovery up to 7 days.
GDPR & DPA ready
Standard Contractual Clauses, signed Data Processing Agreements on request, and a documented data-subject access workflow for every region we serve.
Least-privilege access
Production access requires hardware key 2FA and is logged immutably. Engineers cannot view customer content without an explicit, audited support request.
Responsible disclosure
Found a vulnerability? We respond to every report within 48 hours and credit researchers in our public security acknowledgements once a fix has shipped.
Email security@sassyfolio.com — PGP key available on request.
Sub-processors
We use a short, audited list of sub-processors: AWS (hosting), Cloudflare (edge & DNS), Stripe, PayPal, SSLCommerz, bKash, Nagad, Rocket (payments), Resend (email). The full list with regions is in our DPA.