New — Iris AI drafts your firewall, routing & rate-limit rules. Explore AI features →
Trust Center

Security & Trust

Security is built into how Ngris is designed and operated. This page describes what we do today and what we are working toward. We aim to describe our posture accurately — we do not claim certifications we do not hold.

Ngris is an early-stage company. Where a control is planned rather than in place today, we say so. If you are evaluating Ngris for a regulated or high-assurance workload, contact security@ngris.com and we will share our current posture directly and honestly.

Compliance & Certifications

We are transparent about our certification status. Below is where we stand today — nothing here is claimed as held unless it is marked "In place."

SOC 2 Not yet started

We do not hold a SOC 2 report. Pursuing a SOC 2 Type II audit is on our roadmap as we grow; we will update this page when an audit is engaged.

ISO 27001 Not yet started

We do not hold ISO 27001 certification. It is a longer-term goal, expected to follow SOC 2.

GDPR In place

We process personal data in the European Union, with the GDPR as our primary framework: lawful bases, data-subject rights, retention limits, EU data residency, and a Data Processing Addendum for business customers. See our Privacy Policy and DPA.

CCPA / CPRA In place

Privacy disclosures, right-to-know/delete/correct, and opt-out of "sale"/"sharing" are supported. We do not sell personal information. See our Privacy Policy.

PCI DSS Not in scope

Payment data is handled entirely by Stripe (a PCI DSS Level 1 provider). Ngris never stores or processes raw cardholder data.

HIPAA Not supported

Ngris is not currently set up to support Protected Health Information (PHI) and does not sign Business Associate Agreements. Do not use Ngris to process PHI at this time.

Data Encryption

  • In transit: TLS 1.3 on public ingress, with HTTP/2 and HTTP/3 (QUIC) support. Traffic between the agent and the edge, and between clients and the edge, is encrypted.
  • At rest: Sensitive customer configuration (auth tokens, webhook secrets, endpoint credentials) is encrypted at the application layer before storage.
  • Passwords: Hashed with bcrypt. Plaintext passwords are never stored.
  • Mutual TLS: Per-endpoint client-certificate enforcement is available, rejecting invalid clients at the TLS handshake. See the docs.

Access Control & Authentication

  • Customer authentication: Token-based API authentication with per-object authorization checks. Single sign-on via SAML 2.0 and OIDC is available on paid plans.
  • Multi-factor authentication: TOTP-based 2FA is available on accounts.
  • Role-based access control: Named roles and per-resource permissions for team accounts, with audit logging of sensitive changes.
  • Internal access: Access to production systems is limited to authorized personnel and protected by strong authentication. We are formalizing least-privilege and access-review processes as the team grows.

Application Security

  • Secure development: Changes go through code review, and we run internal security reviews on security-sensitive features.
  • Dependency & secret scanning: We use automated scanning of dependencies and check for committed secrets in our pipeline.
  • Independent testing (planned): We intend to engage third-party penetration testing and to run a coordinated vulnerability-disclosure program as we grow. We do not currently operate a paid bug-bounty program.

Infrastructure & Network Security

  • Container isolation: Services run in containers under Kubernetes. Application workloads run with reduced privileges.
  • Network segmentation: Databases and internal components are on private networks and are not directly exposed to the public internet.
  • Edge protections: Application-layer rate limiting, WAF rules, IP/geo restrictions, and bot-management rules can be configured per endpoint.
  • Multi-region edge: We operate edge presence in multiple regions to serve traffic closer to users.
  • EU data residency: Customer personal data is stored and processed in the European Union. A limited set of sub-processors (see below) may process specific data elsewhere where their service requires it — most notably Stripe for payments. See our DPA for the transfer safeguards that apply.

Data Retention & Deletion

  • Inspector data: Captured request/response data is retained according to your plan's retention window and automatically purged afterward. Full request/response bodies are only captured when the Inspector is explicitly enabled on an endpoint.
  • Account deletion: When you close your account, we delete your personal data within 30 days, except where we are required to retain it by law. See our Privacy Policy.
  • Secret redaction: The Inspector masks common secrets (API keys, tokens, passwords) in captured data.

Subprocessors

The main third parties we rely on to deliver the service. Contact us for the current, detailed list referenced in our DPA.

Vendor Purpose Location
StripePayment processingUS (PCI Level 1)
CloudflareDNS and network servicesGlobal
Google Analytics 4Aggregate website analytics — loaded only with consent (Consent Mode v2; off by default in the EEA/UK)US / EU
Email delivery providerTransactional emailUS / EU

We will give business customers reasonable advance notice of new subprocessors that materially affect the processing of their data, as described in the DPA.

Incident Response

  • Monitoring: We monitor the platform and investigate anomalies. Service status is published at our status page.
  • Breach notification: If a security incident affects your personal data, we will notify affected customers and, where applicable, supervisory authorities within the timelines required by GDPR, CCPA, and other applicable law.
  • Post-incident review: We conduct reviews of significant incidents to identify and address root causes.

Report a Vulnerability

If you believe you've found a security vulnerability, please report it responsibly to security@ngris.com.

  • Good-faith safe harbor: We will not pursue legal action against researchers who report vulnerabilities in good faith, avoid privacy violations and service disruption, and give us reasonable time to remediate before disclosure.
  • Acknowledgement: We aim to acknowledge reports promptly and keep you informed as we investigate.

Security & Procurement Questions

Evaluating Ngris and need more detail — a DPA, our current subprocessor list, or answers to a security questionnaire? Reach out and we will respond honestly about what we have in place today.

Ask an AI to summarise this page