Security
Security Policy
At a glance
We take security seriously. Your data is encrypted, access is controlled, and we follow industry best practices.
1. Our Commitment to Security
Devitify is committed to protecting the confidentiality, integrity, and availability of our systems and your data. Security is built into every layer of our platform, from infrastructure to application code.
2. Data Encryption
- All data in transit is encrypted using TLS 1.2 or higher.
- Sensitive data at rest is encrypted using AES-256 encryption.
- Database connections use encrypted channels with certificate verification.
3. Authentication & Access Control
- Multi-step authentication with email verification codes and passwords.
- Role-based access control (RBAC) with granular permission levels.
- JWT-based session management with short-lived access tokens and secure refresh tokens.
- Automatic session expiration and token rotation.
4. Infrastructure Security
- Cloud infrastructure hosted on industry-leading providers with SOC 2 compliance.
- Network isolation with firewall rules and private subnets.
- Regular security patches and system updates.
- Automated monitoring and alerting for suspicious activity.
5. Application Security
- Input validation and sanitization to prevent injection attacks.
- CSRF protection on all state-changing operations.
- Rate limiting to prevent brute-force and abuse.
- Content Security Policy (CSP) headers to mitigate XSS.
- Regular dependency audits and vulnerability scanning.
6. Data Backup & Recovery
We perform regular automated backups of all critical data. Backups are encrypted and stored in geographically separate locations. Our recovery procedures are tested periodically to ensure business continuity.
7. Incident Response
In the event of a security incident, we follow a structured incident response process including identification, containment, eradication, and recovery. Affected users will be notified promptly in accordance with applicable regulations.
8. Responsible Disclosure
If you discover a security vulnerability, we encourage responsible disclosure. Please report it to info@devitify.fr and we will respond promptly. We do not take legal action against researchers who act in good faith.
9. Contact
For security-related questions or to report a concern, contact us at info@devitify.fr.