-
Use Cases
-
Resources
-
Pricing
We are dedicated to the security of your data.
Last updated: February 7, 2022
We follow industry best practices, so security is built into our product and into our regular development process, which includes code reviews, unit tests, and integration tests.
All engineers are required to know the OWASP vulnerabilities and to use libraries, frameworks, and mitigations vetted and recommended by the security community.
We regularly update our servers, tools, and libraries, and patch vulnerabilities as they are discovered. Our application, host, and network are automatically scanned. We also automatically detect out-of-date dependencies.
All data in transit runs over SSL. All passwords are hashed with bcrypt, and billing information is handled entirely by our PCI-compliant payment providers (Stripe and PayPal).
Secrets are stored securely and never in source code. Access to our infrastructure and related services requires SSH and, where possible, two-factor authentication.
We are committed to keeping Preceden highly available. Our infrastructure runs on fault-tolerant systems, and backups are made daily. Redundant third-party providers give us 24/7 monitoring and alerting for any downtime.
Preceden is hosted on DigitalOcean, a cloud infrastructure provider serving customers worldwide. Preceden is deployed to DigitalOcean's New York region (NYC1). For information about data residency, see DigitalOcean's data center locations.
DigitalOcean operates SOC 2 Type II audited data centers and complies with major industry standards including:
We welcome responsible security research and disclosure involving our product and infrastructure. Report potential vulnerabilities to [email protected]. Valid findings will be considered for compensation.