Trust & Security

Security is built into everything we do

Protecting your data isn't a feature - it's the foundation. Here's how we keep KubixDesiney and your business secure.

Encryption everywhere

All data is encrypted in transit with TLS and at rest. Passwords are salted and hashed - never stored in plain text.

Access control

Role-based permissions and database row-level security enforce least-privilege access, so people and systems only see what they should.

Hardened infrastructure

The platform runs on enterprise-grade, SOC 2-compliant cloud infrastructure with network isolation, managed patching, and automated backups.

Secure engineering

We follow secure development practices, validate inputs, monitor dependencies for vulnerabilities, and ship changes through reviewed pipelines.

Monitoring & resilience

Activity is logged and monitored, data is backed up regularly, and we maintain an incident-response process to act quickly when needed.

Privacy by design

We minimize the data we collect, process it lawfully, and hold our vendors to data-protection agreements. See our Privacy Policy for details.

Compliance & privacy

Designed for global compliance

Our data practices are aligned with the GDPR, UK GDPR, and CCPA/CPRA. We process personal data lawfully, support data-subject rights, and hold our sub-processors to written data-protection agreements. Data residency and processing terms are available for enterprise customers on request.

In place today
Encryption in transit (TLS) and at rest
Role-based access control and row-level security
Built on SOC 2-compliant cloud infrastructure
GDPR and CCPA-aligned data practices
Email verification and secure authentication
Encrypted, managed database backups
On our roadmap
SOC 2 Type II (independent audit)In progress
ISO 27001 certificationPlanned
Independent penetration testingPlanned
Public status page & uptime SLAPlanned

Responsible disclosure

Found a potential vulnerability? We appreciate responsible disclosure. Email [email protected] with the details and we'll investigate promptly. Please give us reasonable time to remediate before any public disclosure.

Incident response and breach notification

We monitor our systems and dependencies for signs of compromise, and incidents can also reach us through a customer report or our responsible-disclosure channel below. Every suspected incident is triaged immediately to establish what happened, whether personal data was involved, and who is affected.

If a personal data breach affects your data, we will notify you without undue delay - and in any event within 48 hours of becoming aware of it - leaving you time to meet your own regulatory notification duties (for example, the GDPR's 72-hour window). That notification will set out, to the extent known at the time: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures we've taken or propose to take in response.

[email protected] is our single point of contact for incident communications, and we'll work directly with your team to support your own notification obligations to regulators and affected individuals.

Talk to us

Questions about security or compliance?

Our team is happy to walk through our security posture, share documentation, and answer your due-diligence questions.

[email protected]