How we protect your data and ensure compliance
JWT-based authentication with SHA-256 session hashing. Multi-factor authentication (TOTP RFC 6238) with backup codes. SSO via Okta, Microsoft Entra ID, Login.gov, SAML 2.0, and OIDC.
Role-based access control with admin, tester, and viewer roles. Organization-level roles (owner, admin, member). Route-level authorization middleware on all protected endpoints.
AES-256-GCM encryption for sensitive database fields (MFA secrets, integration tokens). Passwords hashed with bcrypt (12 salt rounds). TLS 1.2+ for all data in transit. HSTS with 1-year max-age and preload.
Comprehensive audit trail for all API requests, authentication attempts, RBAC violations, and security events. Request ID tracking (X-Request-ID) for full traceability. Structured JSON logs with Winston.
Helmet security headers (CSP, X-Frame-Options DENY, HSTS, noSniff). CORS with strict origin whitelist. Rate limiting (300/min general, 20/min AI). CSRF protection via custom header validation. SSRF prevention (blocks private IPs, loopback, AWS metadata).
FedRAMP-ready architecture with three security profiles: Enterprise, Government, and Classified. NIST 800-53 control mapping (AC-2, AU-2, AU-3, IA-2, SC-8, SC-13). SOC2-aligned security controls. HIPAA-ready data handling.
If you discover a security vulnerability in our platform, please report it responsibly to help@techtonicinnovations.com. We will acknowledge receipt within 24 hours and aim to resolve critical issues within 72 hours.
Security inquiries: help@techtonicinnovations.com
NexGen QA Systems Inc., San Francisco, CA, United States