Security

Security

Effective Date: July 19, 2025

Security Practices

At WASViking, security is embedded in every layer of our platform. Below is an overview of the practices we implement to protect data and ensure service integrity:

Data Encryption
  • All data in transit is protected using TLS 1.2 or higher.
  • All data at rest is encrypted using AES-256.
Access Control
  • Role-based access control (RBAC) with least-privilege principles.
  • Multi-factor authentication (MFA) enforced for admin users.
  • All access is logged and continuously monitored.
Secure Infrastructure
  • Hosted on Amazon Web Services (AWS) with layered protections (WAF, VPC, IAM).
  • Security updates and patches are applied regularly across the environment.
Development Practices
  • Secure Development Lifecycle (SDLC) with code reviews and static code analysis.
  • Dependency management with vulnerability monitoring.
  • Secrets and credentials are managed securely.
Monitoring & Response
  • 24/7 monitoring and anomaly detection.
  • Incident response procedures in place and regularly tested.
  • Periodic third-party penetration tests.
Sensitive Data Handling (Exposure Intelligence)

WASViking includes features designed to identify potential exposure of sensitive data, such as credentials, email addresses, and related security indicators.

  • Sensitive fields are masked by default and require explicit user action to be revealed;
  • All access to sensitive data may be logged and audited for security and abuse prevention;
  • Access is restricted based on role-based permissions (RBAC) and least-privilege principles;
  • Data is processed solely for legitimate security purposes, including risk identification and remediation;
  • We do not enrich, correlate, or use such data for profiling or marketing purposes.

Customers are responsible for ensuring that access to sensitive data is limited to authorized personnel and complies with applicable data protection and privacy laws.

Compliance
  • Practices aligned with GDPR, LGPD, and CCPA.
  • Data Processing Agreement (DPA) available upon request.
Contact Information

For detailed questions, contact our team:
WASViking LLC
Orlando, FL, USA
[email protected]

Up

Florida, United States