Program Overview
Equiforge operates an information security program aligned with ISO/IEC 27001, ISO/IEC 42001, SOC 2 Trust Services Criteria, and PCI-DSS v4.0. The program is owned by the Chief Information Security Officer and reviewed at least annually by executive leadership.
Encryption
- In transit: TLS 1.3 with modern cipher suites for all customer-facing endpoints.
- At rest: AES-256 for databases, object storage, and backups.
- Key management: Hardware-backed key storage with documented rotation cadence.
Access Controls
- Single sign-on and mandatory multi-factor authentication for all production access.
- Role-based access control with least-privilege defaults and quarterly access reviews.
- All production changes logged and reviewed.
Secure Development Lifecycle
Code is reviewed before merge, scanned with static analysis, and dependencies are continuously monitored for known vulnerabilities. Penetration tests are conducted at least annually by an independent third party.
Vulnerability Disclosure
Report security issues to security@equiforge.ai. We commit to acknowledging reports within two (2) business days. Researchers acting in good faith under this policy will not be subject to legal action.
Incident Response
We maintain a documented incident response plan with defined roles, severity classifications, and notification SLAs. Customers are notified of confirmed incidents affecting their data without undue delay and in accordance with applicable law.
Data Residency
Customer data is primarily processed in U.S. regions. Specific data-residency commitments are available upon request to security@equiforge.ai.
Sub-processors
A current list of sub-processors is provided in Annex III of our Data Processing Agreement.
Certifications
See the certifications page for current scope, issuing bodies, and report access procedures.