Security Policy
Our commitment to keeping your data safe and secure.
1. Overview
At Bot Forge, security is a shared responsibility. We employ comprehensive measures across infrastructure, applications, and processes to safeguard your data.
2. Infrastructure Security
Our hosting environment features:
- Enterprise-grade cloud platforms (AWS, Azure).
- 24/7 monitoring and automated alerts.
- DDoS mitigation and network firewalls.
- Regular vulnerability scans and penetration testing.
- Automated, encrypted backups with geo-redundancy.
3. Application & Data Protection
We secure your data in transit and at rest:
- TLS encryption for all data in transit.
- AES-256 encryption for stored data.
- Secure coding practices and code reviews.
- Role-based access controls and multi-factor authentication for staff.
4. Compliance & Certifications
We adhere to industry standards to ensure robust security:
- GDPR compliant for data protection in the EU.
- SOC 2 Type II audited controls.
- ISO 27001 certified information security management.
- Regular third-party compliance audits.
5. Security Best Practices
For your account safety, we recommend:
- Using strong, unique passwords (passphrases preferred).
- Enabling two-factor authentication (2FA).
- Keeping your software and devices updated.
- Reviewing your account activity regularly.
6. Incident Response
In the event of a security incident:
- Our team will assess and contain the issue immediately.
- Affected users will be notified within 72 hours.
- We’ll provide post-incident reports and remediation steps.
7. Reporting Security Issues
If you discover a vulnerability, please contact us at security@botforge.ai. We take all reports seriously and respond promptly.