Security at A2UI
Your data security is our top priority. We implement enterprise-grade security measures to protect your landing pages, leads, and business data.
SOC 2 Type II
In Progress
Expected: Q2 2025
ISO 27001
Planned
Expected: Q4 2025
GDPR
Compliant
India IT Act
Compliant
Encryption Everywhere
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Database encryption, backup encryption, and key management through AWS KMS.
- AES-256 encryption at rest
- TLS 1.3 in transit
- AWS KMS key management
- Encrypted backups
- Field-level encryption for PII
Infrastructure Security
Hosted on AWS (Mumbai region) with enterprise-grade security. Multi-AZ deployment, auto-scaling, and DDoS protection.
- AWS Mumbai region (ap-south-1)
- Multi-AZ deployment
- Auto-scaling infrastructure
- AWS WAF & Shield
- VPC isolation
- Private subnets
Data Isolation
Multi-tenant architecture with strict data isolation. Each tenant's data is logically separated with row-level security policies.
- Logical data isolation
- Row-level security (RLS)
- Tenant-scoped API keys
- Isolated analytics
- No cross-tenant data access
Penetration Testing
Regular penetration testing by independent security firms. Automated vulnerability scanning and SAST/DAST in CI/CD pipeline.
- Annual third-party pen testing
- Monthly vulnerability scans
- SAST in CI/CD pipeline
- Dependency scanning
- Container image scanning
Access Control
Role-based access control (RBAC), multi-factor authentication (MFA), and SSO/SAML support for enterprise customers.
- Role-based access control
- Multi-factor authentication
- SSO / SAML (Enterprise)
- API key management
- Audit logging
- Session management
Compliance
Compliant with GDPR, India IT Act, and industry best practices. Working toward SOC 2 Type II certification.
- GDPR compliant
- India IT Act compliant
- SOC 2 Type II (in progress)
- ISO 27001 (planned)
- RERA-ready templates
- Data processing agreements
Responsible Disclosure
We welcome security researchers to report vulnerabilities responsibly. If you discover a security issue, please email security@a2ui.io. We respond within 24 hours and offer recognition for valid reports.
Scope
- • app.a2ui.io (main application)
- • api.a2ui.io (API endpoints)
- • *.a2ui.io (subdomains)
Out of Scope
- • Social engineering attacks
- • DDoS attacks
- • Third-party services
Questions About Security?
Our security team is happy to discuss our practices in detail.