Trust & Security
Built to earn your trust
Zeridion is committed to the security, privacy, and reliability of customer data. This page summarises our security posture, uptime record, data subprocessors, and links to our full legal documentation.
Uptime
We target 99.9% monthly uptime for the Flare API and dashboard.
99.95%last 30 days
Real-time surface checks are available on status.zeridion.com. Incident history is posted below and on the status page.
Security posture
- Encryption at rest — all customer data stored in Azure Database for PostgreSQL Flexible Server, which encrypts data at rest using AES-256 by default.
- Encryption in transit — all traffic between clients, the Flare API, and internal services is encrypted with TLS 1.2+. HTTP connections are redirected to HTTPS.
- Key management — secrets and connection strings are stored in Azure Key Vault and rotated on a scheduled basis. Application credentials are never baked into container images.
- Audit logging — every API request that mutates state (enqueue, cancel, update) is appended to an immutable audit log tied to the tenant project ID. Logs are retained for 90 days.
- Access control — API keys are scoped per project. Dashboard access requires email-verified accounts with bcrypt-hashed credentials. Rate limiting is applied per tenant using a sliding-window algorithm backed by Redis.
- Vulnerability disclosure — found an issue? Email security@zeridion.com. We aim to acknowledge within 24 hours and resolve critical issues within 7 days.
Full details are in the Security policy.
Subprocessors
The following third parties may process customer data on behalf of Zeridion. We will give 30 days' notice before adding a new subprocessor — email privacy@zeridion.com to subscribe to announcements.
| Subprocessor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Compute, managed Postgres, managed Redis, networking | See DPA |
| SendGrid (Twilio) | Transactional email (signup verification, alert emails) | See DPA |
| Stripe | Subscription billing and payment processing | See DPA |
Full list maintained in the Subprocessors page.