Your security is our top priority. We implement industry-leading practices to protect your data.
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Your code and secrets are always protected.
We maintain SOC 2 Type II compliance with annual audits by independent third-party security firms.
Role-based access control (RBAC), SSO support via SAML/OIDC, and comprehensive audit logs for all activity.
Environment variables and secrets are encrypted and never exposed in logs or build outputs.
DDoS protection, WAF, and isolated network environments for each deployment.
We run an active bug bounty program. Responsible disclosure is rewarded generously.
Found a security issue? We take all reports seriously and respond within 24 hours. Responsible disclosure is rewarded through our bug bounty program.
security@shipyard.dev