On this page
Certifications Encryption Isolation & access Resilience Responsible disclosure Sub-processors & uptime

Legal

Security

Last updated May 1, 2026 · Questions? contact us.

Security is part of the runtime, not a bolt-on. This page summarises how we protect your graphs, data and credentials — and how to report an issue.

Certifications

We maintain independent attestations and align our controls to recognised standards:

  • SOC 2 Type II — audited annually.
  • ISO 27001 — certified information-security management.
  • GDPR & UK GDPR — with a DPA available for all customers.

Encryption

Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Secrets are stored in an isolated vault, scoped per node, and never written to run logs.

Isolation & access

Each tenant runs in an isolated execution context. Internal access follows least-privilege, requires SSO and hardware keys, and is logged and reviewed.

Resilience

The runtime is multi-region with automated failover. Backups are encrypted, tested by restore, and retained per policy. Durable runs let workloads survive infrastructure events.

Responsible disclosure

Found a vulnerability? We want to hear from you. Email security@fix.net with details; we acknowledge within 48 hours and run a coordinated-disclosure program with researcher recognition.

Sub-processors & uptime

Our infrastructure providers are bound by security and data-processing terms. Live availability is published on the status page.