Encryption in transit (TLS 1.3 + HSTS), at rest (disk/snapshots/R2 SSE), selective field encryption (pgcrypto).
MonkeyMachine — SECURITY TOMs SUMMARY
1. ENCRYPTION
2. ACCESS CONTROL
Access control: least privilege, staff MFA, separated roles.
3. ISOLATION & LOGGING
RLS multi‑tenant isolation, centralized logging, SAST/DAST, vulnerability management (critical ≤72h).
4. BACKUP & RECOVERY
Backups/DR (RPO ≤24h; RTO ≤8h), WAF/rate‑limiting, incident response (≤72h notice).
5. TESTING & POLICIES
Annual external pen‑test, quarterly internal reviews, device policy (full‑disk encryption, auto‑lock, VPN/SSO).
Questions? Contact us at
legal@monkeymachine.ru