Trust & Compliance Center

Infrastructure Security & Compliance

At Abrdan, data integrity, low latency runtime protection, and multi-tenant isolation are structural priorities built directly into our baseline lifecycle.

1. Compliance & Security Frameworks

Our microservices, data pipeline layers, and multi-tenant architectures are engineered from the ground up to support strict US and international standards.

SOC 2 Type II Audited
ISO/IEC 27001
GDPR Compliant
CCPA Certified

2. Data Encryption Ciphers

In Transit: All web connections, API payloads, and custom real-time event distribution streams require HTTP/2 or HTTP/3 over TLS 1.3 cryptographic layers with Perfect Forward Secrecy (PFS).

At Rest: Underlying cluster persistence points, database states controlled via MongoDB/Mongoose, and persistent volume backups are securely formatted under AES-256 block-level disk encryption with independent automated KMS key rotations.

3. Vulnerability Management & Bug Bounty

We run continual automated software composition analysis (SCA) and static application security testing (SAST) over our internal GitHub repositories to prevent logic leaks or outdated module injection.

Responsible Disclosure Policy: If you identify a structural security flaw or network vector within Abrdan systems, do not disclose it publicly. Please transmit a comprehensive encrypted breakdown directly to We reward verified critical discoveries under an organized private bounty tier.

4. IAM & Infrastructure Access Control

Abrdan operational engineers enforce Zero Trust Network Access (ZTNA) models. Production cluster nodes are unreachable via public IP space; internal platform debugging mandates temporary time-boxed authorization keys generated over zero-trust hardware MFA tokens. Full logging telemetry aggregates automatically to write-once un-alterable storage vaults.