Security
Our commitment to keeping your data safe and secure
Data Encryption
All data transmitted between your applications and Togglefox is encrypted using industry-standard TLS (Transport Layer Security) protocols. Data at rest is encrypted using AES-256 encryption to ensure your feature flags and configuration remain secure.
Authentication & Access Control
We implement robust authentication mechanisms including:
- Secure password hashing using bcrypt
- API key authentication for programmatic access
- Role-based access control (RBAC) for team members
- Session management with secure tokens
Infrastructure Security
Our infrastructure is designed with security in mind:
- Regular security updates and patches
- Firewall protection and network segmentation
- Intrusion detection and monitoring systems
- Regular security audits and vulnerability assessments
- DDoS protection and mitigation
Data Privacy
We are committed to protecting your privacy:
- We never sell your data to third parties
- Data is only accessed by authorized personnel for service operations
- Compliance with GDPR and other privacy regulations
- Regular privacy impact assessments
Backup & Disaster Recovery
To ensure data availability and integrity:
- Automated daily backups of all data
- Backups stored in geographically distributed locations
- Regular backup restoration testing
- Disaster recovery procedures in place
Compliance & Certifications
We maintain compliance with industry standards and regulations, including:
- GDPR (General Data Protection Regulation)
- Industry best practices for data security
- Regular third-party security assessments
Security Monitoring
We continuously monitor our systems for security threats:
- 24/7 security monitoring and alerting
- Automated threat detection systems
- Security incident response procedures
- Regular security log reviews
Reporting Security Issues
If you discover a security vulnerability, please report it responsibly. We appreciate your help in keeping Togglefox secure. Please email security concerns to security@togglefox.dev and include:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact assessment
- Your contact information
We will acknowledge receipt within 48 hours and work with you to resolve the issue.
Your Security Responsibilities
While we work hard to secure our platform, you also play a crucial role:
- Use strong, unique passwords for your account
- Keep your API keys secure and rotate them regularly
- Enable two-factor authentication when available
- Review and manage team member access regularly
- Report any suspicious activity immediately
Questions About Security?
If you have questions about our security practices, please contact us at security@togglefox.dev or through our contact page.