TRUST / SECURITY

Least privilege. Encrypted everywhere.

IAM scoped per role. AWS KMS at rest. TLS 1.2+ in transit. VPC endpoints for S3 and Glue. SOC 2 Type II audit underway.

AES-256
At rest (KMS)
TLS 1.2+
In transit
SOC 2 II
Audit in progress

Identity and access

AWS IAM roles are scoped to the minimum action set per service. No long-lived access keys for production. STS short-lived credentials only. Human access via SSO. MFA enforced.

Encryption

Surface Mechanism Key custody
S3 raw + Iceberg SSE-KMS, customer-managed key AWS KMS, account-owned
RDS metadata AES-256 at rest, TLS in flight AWS KMS
NebulaGraph storage EBS gp3 encrypted AWS KMS
Backups Cross-region replicated, encrypted AWS KMS
Customer file dropoff SSE-KMS + presigned URLs Customer or shared key

Network

Application security

Compliance posture

Incident response

24/7 on-call. PagerDuty rotation. Documented runbooks for data exposure, credential leak, and pipeline failure. Customer notification within contractual SLA, never longer than what applicable law requires for a personal-data breach.

Related