Security

Our commitment to keeping your data safe and secure

Data Encryption

All data transmitted between your applications and Togglefox is encrypted using industry-standard TLS (Transport Layer Security) protocols. Data at rest is encrypted using AES-256 encryption to ensure your feature flags and configuration remain secure.

Authentication & Access Control

We implement robust authentication mechanisms including:

  • Secure password hashing using bcrypt
  • API key authentication for programmatic access
  • Role-based access control (RBAC) for team members
  • Session management with secure tokens

Infrastructure Security

Our infrastructure is designed with security in mind:

  • Regular security updates and patches
  • Firewall protection and network segmentation
  • Intrusion detection and monitoring systems
  • Regular security audits and vulnerability assessments
  • DDoS protection and mitigation

Data Privacy

We are committed to protecting your privacy:

  • We never sell your data to third parties
  • Data is only accessed by authorized personnel for service operations
  • Compliance with GDPR and other privacy regulations
  • Regular privacy impact assessments

Backup & Disaster Recovery

To ensure data availability and integrity:

  • Automated daily backups of all data
  • Backups stored in geographically distributed locations
  • Regular backup restoration testing
  • Disaster recovery procedures in place

Compliance & Certifications

We maintain compliance with industry standards and regulations, including:

  • GDPR (General Data Protection Regulation)
  • Industry best practices for data security
  • Regular third-party security assessments

Security Monitoring

We continuously monitor our systems for security threats:

  • 24/7 security monitoring and alerting
  • Automated threat detection systems
  • Security incident response procedures
  • Regular security log reviews

Reporting Security Issues

If you discover a security vulnerability, please report it responsibly. We appreciate your help in keeping Togglefox secure. Please email security concerns to security@togglefox.dev and include:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact assessment
  • Your contact information

We will acknowledge receipt within 48 hours and work with you to resolve the issue.

Your Security Responsibilities

While we work hard to secure our platform, you also play a crucial role:

  • Use strong, unique passwords for your account
  • Keep your API keys secure and rotate them regularly
  • Enable two-factor authentication when available
  • Review and manage team member access regularly
  • Report any suspicious activity immediately

Questions About Security?

If you have questions about our security practices, please contact us at security@togglefox.dev or through our contact page.