At rest
AES-256 envelope encryption. Per-tenant keys, quarterly rotation, KMS-backed.
Security
Encryption, region pinning, least-privilege access, annual SOC 2 Type II, and a public responsible-disclosure program with paid bounties. If something is wrong, we want to know — and we act fast.
SOC 2 Type II
annually audited
GDPR & CCPA
compliant
99.98%
uptime, 12-mo trailing
AES-256
encryption at rest
Section 01
Data is encrypted at rest with AES-256 and in transit with TLS 1.3. Database snapshots, backups, and customer-uploaded files inherit the same envelope encryption. Per-tenant data keys are rotated quarterly and stored in a dedicated KMS.
We use a strict HSTS preload, certificate pinning on the mobile and PWA clients, and HTTP-only, SameSite=Lax session cookies. We do not log or store your password in plaintext — we store an Argon2id hash with a per-account salt and a global pepper kept in a separate secrets manager.
AES-256 envelope encryption. Per-tenant keys, quarterly rotation, KMS-backed.
TLS 1.3 only, HSTS preload, modern cipher suites, no RC4, no MD5.
Memory-safe runtimes where possible, ASLR, control-flow integrity, signed builds.
3
independent cloud regions (EU, US-East, US-West)
99.98%
uptime, 12-month trailing average
RPO 5m
recovery point objective, cross-region replication
RTO 1h
recovery time objective, quarterly DR drills
Section 02
fruityworx runs on hardened AWS infrastructure across three independent regions. Pick EU (Frankfurt) or US (Virginia) at signup — your data stays there. Enterprise customers can pin storage to a specific region and negotiate a dedicated tenant.
Backups are encrypted, replicated to a second region, and tested weekly. We run quarterly disaster-recovery drills that simulate full regional loss, and the resulting RTO and RPO are reported in the customer trust portal.
Section 03
The boring stuff that keeps the lights on. The interesting stuff that we run as code.
Every employee gets the minimum access they need to do their job, and only for as long as they need it. Production access requires a hardware security key and an approved change ticket. Access reviews happen every 30 days.
SOC 2 Type II renewed annually by an independent third party. GDPR Data Processing Addendum and Standard Contractual Clauses available on request. Report summaries shared with qualified prospects under NDA.
SAML/OIDC single sign-on, SCIM provisioning, and immutable audit logs on the Orchard plan. Two-factor authentication is available — and recommended — for every plan, including free.
Independent penetration tests twice a year, plus a continuous bug-bounty program. Code review is required for every change touching authentication, payments or encryption.
AI Studio runs against your tenant with strict isolation. Your data is never used to train shared models, and prompts are not retained beyond the request unless you opt in to history.
Every sub-processor is reviewed for security posture, signed to a Data Processing Addendum, and listed publicly at /security#subprocessors.
Section 04
We have a written, rehearsed incident response plan with named roles, an on-call rotation, and a 15-minute target for severity-1 ack. Customers on paid plans get a real-time status feed at /status, and post-incident reports land in the trust portal within 72 hours of resolution.
We notify affected customers without undue delay, and in any case within 72 hours of confirming a personal-data incident — faster than GDPR requires. We will tell you what happened, what was affected, what we did, and what we are changing to keep it from happening again.
Severity-1 targets
Acknowledge
on-call engineer paged and responding within 15 minutes
Mitigate
active customer impact contained within 1 hour
Disclose
customer notification and post-incident report within 72 hours
Bug bounty
We run a public responsible-disclosure program with cash rewards. Critical findings pay up to $5,000.
Email: security@fruityworx.io (PGP key on request)
PGP fingerprint: 4F2A 9C71 8BD3 5E60 11A2
Response SLA: first reply within 24 hours, triage within 72 hours
In scope
*.fruityworx.com web app, mobile clients, the public API at api.fruityworx.com, the PWA service worker.
Out of scope
Denial of service, social engineering of our staff, physical attacks, third-party platforms we integrate with but do not operate.
Our commitment
No legal action against good-faith researchers who follow this policy. We will acknowledge your report, keep you informed, and credit you in the public hall of fame if you want it.
Full SOC 2 report, pen-test summary, and security questionnaire answers — under NDA, in your hands in 48 hours.