Security from the ground up
Six layers of protection, from encryption to compliance to disclosure.
Encryption everywhere
Data is encrypted in transit with TLS 1.2+ and at rest. Sensitive integration credentials are AES-encrypted with per-environment keys — never stored in plaintext.
Hardened infrastructure
Hosted on managed, isolated cloud infrastructure with network segmentation, automated patching, encrypted backups, and continuous monitoring.
Access controls
Role-based permissions, granular per-object access, optional SSO/SAML, and full audit logging keep every action attributable and least-privilege by default.
Data residency
Strict multi-tenant isolation keyed on your organisation. Enterprise customers can choose regional data residency across our Toronto and Tallinn regions.
Compliance
Built to SOC 2 Type II controls and GDPR. A Data Processing Agreement (DPA) and security questionnaire support are available for Enterprise.
Responsible disclosure
We welcome security research. Report a vulnerability to security@autometa.in and we'll acknowledge it quickly and work with you to resolve it.
Subprocessors
We use a small set of vetted infrastructure providers to deliver the service. Each is bound by data-protection terms.
Found a vulnerability?
We take reports seriously and respond fast. Email security@autometa.in with the details.