Security

Enterprise security.
Built in from day one.

EPCdoc is designed with security as a first principle — not an afterthought. Every layer of the platform is hardened for enterprise EPC environments handling sensitive engineering data.

Security Architecture

How we protect your project data.

🔐
Data Encryption
  • AES-256 encryption at rest for all stored documents, drawings, and data
  • TLS 1.3 encryption for all data in transit — no unencrypted connections
  • Database encryption at the volume level on all storage infrastructure
  • Encryption keys managed through hardware security modules (HSM)
🏗️
Multi-Tenant Isolation
  • Per-tenant PostgreSQL schema isolation — complete data separation
  • No cross-tenant data access possible at the database level
  • Separate storage buckets per tenant for document storage
  • Network-level isolation between tenant environments
🔑
Authentication & Access
  • JWT-based authentication with rotating refresh tokens
  • Multi-factor authentication (MFA) with RFC 4648 TOTP
  • 134 role-based permission levels with granular access control
  • Per-route rate limiting — brute force protection on all auth endpoints
  • Session invalidation on password change or suspicious activity
🛡️
Application Security
  • SQL injection prevention — parameterised queries and UUID validation
  • XSS protection — strict Content Security Policy headers
  • CSRF protection on all state-changing operations
  • Input validation and sanitisation on all API endpoints
  • Regular dependency vulnerability scanning (npm audit)
📋
Audit & Compliance
  • Complete audit log — every action timestamped with user, IP, and entity
  • Audit logs partitioned by year for performance and retention compliance
  • Immutable audit trail — logs cannot be deleted by users or admins
  • GDPR-compliant data export for all account data
  • DPDP Act 2023 compliant data handling and residency
🏢
Infrastructure Security
  • Cloud-hosted on hardened Linux servers (AlmaLinux 9)
  • Automated security patches and OS updates
  • Firewall and network access controls at infrastructure level
  • DDoS protection at the edge
  • Regular automated backups with encryption and geographic redundancy
Compliance

Regulatory compliance across jurisdictions.

🇮🇳
India — DPDP Act 2023
Data Principal rights respected
Consent management built-in
Data Protection Officer appointed
Cross-border transfer controls
🇪🇺
EU/UK — GDPR
Article 28 DPA available
Standard Contractual Clauses for transfers
72-hour breach notification
Data subject request handling
🇺🇸
USA — CCPA/CPRA
No sale of personal data
Right to deletion supported
Privacy notice at collection
Opt-out mechanisms available
🌏
Global Standards
ISO 27001 controls implemented
SOC 2 Type II equivalent controls
PCI DSS — no card data stored
OWASP Top 10 mitigations
Responsible Disclosure

Security vulnerability reporting.

If you discover a security vulnerability in EPCdoc, we encourage responsible disclosure. Please report it to our security team before public disclosure. We commit to acknowledging reports within 48 hours and providing updates on remediation.

Report a Vulnerability →

security@tworai.com

💬 Ask me about EPCdoc