Security

Built to be opened
by auditors. Safe enough
to trust with customers.

Encryption, region pinning, least-privilege access, annual SOC 2 Type II, and a public responsible-disclosure program with paid bounties. If something is wrong, we want to know — and we act fast.

SOC 2 Type II

annually audited

GDPR & CCPA

compliant

99.98%

uptime, 12-mo trailing

AES-256

encryption at rest

Section 01

Encryption
everywhere it matters.

Data is encrypted at rest with AES-256 and in transit with TLS 1.3. Database snapshots, backups, and customer-uploaded files inherit the same envelope encryption. Per-tenant data keys are rotated quarterly and stored in a dedicated KMS.

We use a strict HSTS preload, certificate pinning on the mobile and PWA clients, and HTTP-only, SameSite=Lax session cookies. We do not log or store your password in plaintext — we store an Argon2id hash with a per-account salt and a global pepper kept in a separate secrets manager.

At rest

AES-256 envelope encryption. Per-tenant keys, quarterly rotation, KMS-backed.

In transit

TLS 1.3 only, HSTS preload, modern cipher suites, no RC4, no MD5.

In use

Memory-safe runtimes where possible, ASLR, control-flow integrity, signed builds.

3

independent cloud regions (EU, US-East, US-West)

99.98%

uptime, 12-month trailing average

RPO 5m

recovery point objective, cross-region replication

RTO 1h

recovery time objective, quarterly DR drills

Section 02

Infrastructure
you can pin to a region.

fruityworx runs on hardened AWS infrastructure across three independent regions. Pick EU (Frankfurt) or US (Virginia) at signup — your data stays there. Enterprise customers can pin storage to a specific region and negotiate a dedicated tenant.

Backups are encrypted, replicated to a second region, and tested weekly. We run quarterly disaster-recovery drills that simulate full regional loss, and the resulting RTO and RPO are reported in the customer trust portal.

Section 03

Access & compliance.

The boring stuff that keeps the lights on. The interesting stuff that we run as code.

Least-privilege by default

Every employee gets the minimum access they need to do their job, and only for as long as they need it. Production access requires a hardware security key and an approved change ticket. Access reviews happen every 30 days.

Audited & certified

SOC 2 Type II renewed annually by an independent third party. GDPR Data Processing Addendum and Standard Contractual Clauses available on request. Report summaries shared with qualified prospects under NDA.

SSO, SCIM & audit logs

SAML/OIDC single sign-on, SCIM provisioning, and immutable audit logs on the Orchard plan. Two-factor authentication is available — and recommended — for every plan, including free.

Pen tests & reviews

Independent penetration tests twice a year, plus a continuous bug-bounty program. Code review is required for every change touching authentication, payments or encryption.

No model training on your data

AI Studio runs against your tenant with strict isolation. Your data is never used to train shared models, and prompts are not retained beyond the request unless you opt in to history.

Vendor due diligence

Every sub-processor is reviewed for security posture, signed to a Data Processing Addendum, and listed publicly at /security#subprocessors.

Section 04

When something
goes wrong.

We have a written, rehearsed incident response plan with named roles, an on-call rotation, and a 15-minute target for severity-1 ack. Customers on paid plans get a real-time status feed at /status, and post-incident reports land in the trust portal within 72 hours of resolution.

We notify affected customers without undue delay, and in any case within 72 hours of confirming a personal-data incident — faster than GDPR requires. We will tell you what happened, what was affected, what we did, and what we are changing to keep it from happening again.

Severity-1 targets

  • 15

    Acknowledge

    on-call engineer paged and responding within 15 minutes

  • 1h

    Mitigate

    active customer impact contained within 1 hour

  • 72h

    Disclose

    customer notification and post-incident report within 72 hours

Bug bounty

Tell us first.
Get paid.

We run a public responsible-disclosure program with cash rewards. Critical findings pay up to $5,000.

Email: security@fruityworx.io (PGP key on request)

PGP fingerprint: 4F2A 9C71 8BD3 5E60 11A2

Response SLA: first reply within 24 hours, triage within 72 hours

In scope

*.fruityworx.com web app, mobile clients, the public API at api.fruityworx.com, the PWA service worker.

Out of scope

Denial of service, social engineering of our staff, physical attacks, third-party platforms we integrate with but do not operate.

Our commitment

No legal action against good-faith researchers who follow this policy. We will acknowledge your report, keep you informed, and credit you in the public hall of fame if you want it.

Report a vulnerability

Want the long version?

Full SOC 2 report, pen-test summary, and security questionnaire answers — under NDA, in your hands in 48 hours.