A2
A2UI

Security at A2UI

Your data security is our top priority. We implement enterprise-grade security measures to protect your landing pages, leads, and business data.

SOC 2 Type II

In Progress

Expected: Q2 2025

ISO 27001

Planned

Expected: Q4 2025

GDPR

Compliant

India IT Act

Compliant

Encryption Everywhere

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Database encryption, backup encryption, and key management through AWS KMS.

  • AES-256 encryption at rest
  • TLS 1.3 in transit
  • AWS KMS key management
  • Encrypted backups
  • Field-level encryption for PII

Infrastructure Security

Hosted on AWS (Mumbai region) with enterprise-grade security. Multi-AZ deployment, auto-scaling, and DDoS protection.

  • AWS Mumbai region (ap-south-1)
  • Multi-AZ deployment
  • Auto-scaling infrastructure
  • AWS WAF & Shield
  • VPC isolation
  • Private subnets

Data Isolation

Multi-tenant architecture with strict data isolation. Each tenant's data is logically separated with row-level security policies.

  • Logical data isolation
  • Row-level security (RLS)
  • Tenant-scoped API keys
  • Isolated analytics
  • No cross-tenant data access

Penetration Testing

Regular penetration testing by independent security firms. Automated vulnerability scanning and SAST/DAST in CI/CD pipeline.

  • Annual third-party pen testing
  • Monthly vulnerability scans
  • SAST in CI/CD pipeline
  • Dependency scanning
  • Container image scanning

Access Control

Role-based access control (RBAC), multi-factor authentication (MFA), and SSO/SAML support for enterprise customers.

  • Role-based access control
  • Multi-factor authentication
  • SSO / SAML (Enterprise)
  • API key management
  • Audit logging
  • Session management

Compliance

Compliant with GDPR, India IT Act, and industry best practices. Working toward SOC 2 Type II certification.

  • GDPR compliant
  • India IT Act compliant
  • SOC 2 Type II (in progress)
  • ISO 27001 (planned)
  • RERA-ready templates
  • Data processing agreements

Responsible Disclosure

We welcome security researchers to report vulnerabilities responsibly. If you discover a security issue, please email security@a2ui.io. We respond within 24 hours and offer recognition for valid reports.

Scope

  • • app.a2ui.io (main application)
  • • api.a2ui.io (API endpoints)
  • • *.a2ui.io (subdomains)

Out of Scope

  • • Social engineering attacks
  • • DDoS attacks
  • • Third-party services

Questions About Security?

Our security team is happy to discuss our practices in detail.