Security

Your data is protected at every layer

We treat security as a product requirement, not an afterthought. Every architectural decision at Seraph is made with your data's confidentiality, integrity, and availability in mind.

Security controls

Enterprise-grade protection for teams of every size

We implement the same security standards used by regulated industries — so you can audit with confidence.

SOC 2 Type II

Seraph is actively pursuing SOC 2 Type II certification. Our controls covering security, availability, and confidentiality are audited annually by an independent third-party assessor. Certification expected Q4 2026.

In progress — Q4 2026

TLS 1.3 Encryption in Transit

All data transmitted between your browser and Seraph's servers is encrypted using TLS 1.3, the latest and most secure transport layer protocol. We enforce HTTPS across all endpoints — there are no unencrypted fallbacks.

Always-on

AES-256 Encryption at Rest

All data stored in Seraph's databases and object storage is encrypted at rest using AES-256. Encryption keys are managed through AWS Key Management Service (KMS) with automatic annual rotation.

Military-grade

Role-Based Access Control

Access to Seraph's internal systems is governed by least-privilege RBAC. Engineers only have access to the systems they need. All production access is logged, reviewed quarterly, and requires MFA.

Least-privilege

99.9% Uptime SLA

Seraph is designed for high availability with redundant infrastructure across multiple AWS availability zones. We maintain a public status page and notify affected customers proactively during any service degradation.

Multi-AZ redundancy

GDPR & CCPA Compliant

We support data subject access requests, right-to-erasure, and data portability. Our Data Processing Agreement (DPA) is available for customers who require it for GDPR compliance. Contact us at privacy@seraph.ai.

EU & California ready
Infrastructure

Built on AWS with multi-AZ redundancy

Seraph runs on Amazon Web Services (AWS) in the us-east-1 region with failover capacity in us-west-2. Our application tier, database layer, and storage are all deployed across multiple Availability Zones to eliminate single points of failure.

Database backups are performed continuously with point-in-time recovery enabled, and full snapshots are retained for 30 days. All backups are encrypted and stored in a separate AWS account to protect against accidental deletion or account compromise.

Our CI/CD pipeline includes automated security scanning (SAST, dependency vulnerability checks) on every code merge. Infrastructure changes are reviewed by at least two engineers before deployment, and all production changes are logged in an immutable audit trail.

Responsible Disclosure

Found a vulnerability? We want to know.

We take security reports seriously and appreciate the time researchers invest in disclosing vulnerabilities responsibly. If you believe you've discovered a security issue in the Seraph platform, please follow these steps:

  1. Email us privately at security@seraph.ai before public disclosure. Include a detailed description of the vulnerability, steps to reproduce it, and your assessment of its potential impact.
  2. Allow us time to respond. We commit to acknowledging your report within 48 hours and providing a remediation timeline within 10 business days.
  3. Do not exploit the vulnerability or access user data beyond what is necessary to demonstrate the issue.
  4. Co-ordinate disclosure. We ask for a 90-day window to remediate before public disclosure, and we will work with you to co-ordinate timing if needed.
Recognition: We acknowledge all valid, responsibly-disclosed vulnerabilities in our security acknowledgements page. For critical findings, we offer discretionary rewards. Contact security@seraph.ai to begin a disclosure.