Trust Center
Procurement answers
The questions a vendor-risk review asks, answered in one place. Every answer below is either a stated fact with its source, or a statement that it is answered during a security review. Nothing here is estimated.
Where we do not hold something, this page says so plainly rather than describing it in a way that reads like we do.
Answers
| Question | Answer |
|---|---|
| Hosting provider | MSP Reboot (mspreboot.com). |
| Hosting region | Hosted in the Surety Data Center facility (suretydc.com). |
| Data residency | United States. |
| Current subprocessors | MSP Reboot — hosting and infrastructure. Anthropic — processes finding content where the AI security analyst is enabled. Pushover — notification delivery. Vulnerability and threat-intelligence sources are read from, not sent to, and process no customer data. |
| Encryption in transit | HTTPS only. TLS 1.2 and TLS 1.3 are accepted; TLS 1.0 and TLS 1.1 are refused. |
| Stored credential encryption | Integration credentials are encrypted before storage using Fernet (AES-128-CBC with HMAC-SHA256 authentication), with the key derived by PBKDF2-HMAC-SHA256 at 480,000 iterations. |
| Password hashing | bcrypt, through passlib, with automatic rehashing on scheme change. |
| Backup frequency | Daily, replicated to a second data centre. |
| Backup encryption | Backups are encrypted. |
| Last successful recovery test | None performed. Backups exist; a tested recovery has not been carried out, and no recovery time is claimed on the strength of untested backups. |
| RPO and RTO | Provided during a security review. |
| Retention controls | Scan and report retention is configurable per tenant, enforced by a scheduled cleanup that acts on the setting rather than leaving it declarative. |
| Tenant deletion | Deleting a tenant removes its assets, findings, exposure graph and remediation history by cascade. |
| Tenant deletion timing | Immediate. Deletion removes the tenant's records when it is carried out, rather than after a retention window. |
| Incident reporting contact | Reported through the contact route published in /.well-known/security.txt, which names only the route shown to work. |
| Responsible disclosure | Published policy at /security/#disclosure, with a machine-readable /.well-known/security.txt. |
| Data processing agreement | No data processing agreement is available yet. If your procurement process requires one, say so during the security review and it will be answered directly rather than deferred. |
| Vendor questionnaire process | Send the questionnaire through the contact form marked as a security review. It is answered directly, including by a call with an engineer where a document is not what your process needs. |
| Independent assurance | None. There is no SOC 2 report, no ISO 27001 certificate and no independent penetration test. Security testing is carried out by our own engineers and is described as such. |
Send us the questionnaire
Anything this page does not cover is answered directly, including standard vendor-risk questionnaires.