Skip to content

Security & Trust

How we protect your data and ensure compliance

FedRAMP / IL5 Ready Architecture

Authentication

JWT-based authentication with SHA-256 session hashing. Multi-factor authentication (TOTP RFC 6238) with backup codes. SSO via Okta, Microsoft Entra ID, Login.gov, SAML 2.0, and OIDC.

Authorization (RBAC)

Role-based access control with admin, tester, and viewer roles. Organization-level roles (owner, admin, member). Route-level authorization middleware on all protected endpoints.

Encryption

AES-256-GCM encryption for sensitive database fields (MFA secrets, integration tokens). Passwords hashed with bcrypt (12 salt rounds). TLS 1.2+ for all data in transit. HSTS with 1-year max-age and preload.

Audit Logging

Comprehensive audit trail for all API requests, authentication attempts, RBAC violations, and security events. Request ID tracking (X-Request-ID) for full traceability. Structured JSON logs with Winston.

Infrastructure Security

Helmet security headers (CSP, X-Frame-Options DENY, HSTS, noSniff). CORS with strict origin whitelist. Rate limiting (300/min general, 20/min AI). CSRF protection via custom header validation. SSRF prevention (blocks private IPs, loopback, AWS metadata).

Compliance

FedRAMP-ready architecture with three security profiles: Enterprise, Government, and Classified. NIST 800-53 control mapping (AC-2, AU-2, AU-3, IA-2, SC-8, SC-13). SOC2-aligned security controls. HIPAA-ready data handling.

Responsible Disclosure

If you discover a security vulnerability in our platform, please report it responsibly to help@techtonicinnovations.com. We will acknowledge receipt within 24 hours and aim to resolve critical issues within 72 hours.

Contact

Security inquiries: help@techtonicinnovations.com

NexGen QA Systems Inc., San Francisco, CA, United States