Security isn't an afterthought at incident.io—it's a core principle that guides everything from our technology to our team culture.
We’re fully compliant with SOC 2 Type I and II, as well as GDPR, as part of our focus on keeping your data safe and secure.
How we think about security
We encrypt your data using AES-256, the gold standard in encryption technology and safeguard passwords using a secure cryptographic one-way hash function (SHA-256).
We leverage state-of-the-art security measures from industry-leading cloud providers to ensure your data is safe. This means you get the best of both worlds: our expertise and their best-in-class defences.
We ensure our devices are running the latest OS and app versions within a month of their release, with new security updates applied as soon as they're available.
We conduct annual third-party penetration tests and share the results via our Trust center. Weekly scans ensure our product stays resilient against OWASP vulnerabilities and other emerging threats.
Found something? Let us know. Our Responsible Disclosure Policy encourages ethical reporting of vulnerabilities and we’ll assess and respond quickly—our team prioritises security concerns above all else.
We reward those who help us stay secure. Qualifying vulnerabilities reported responsibly may earn you a place in our bug bounty program. We’ll recognise any significant discovery that enhances our security posture.