Built with
security first

Enterprise-grade security for every team — from startups to Fortune 500. Your data is protected at every layer.

Compliance & certifications

SOC 2 Type II
Audited annually
GDPR
EU compliant
CCPA
California compliant
ISO 27001
Certified 2025

Security features

Every tier of your data is protected — from wire encryption to access control.

AES-256-GCM encryption

All data encrypted at rest using AES-256-GCM. Keys are rotated automatically every 90 days.

TLS 1.3 in transit

All traffic encrypted with TLS 1.3. Legacy TLS versions are rejected at the load balancer.

Multi-factor authentication

TOTP-based 2FA is available to all users. SSO via SAML 2.0 / OIDC for Enterprise plans.

Role-based access control

Granular RBAC with Owner, Admin, Agent, and Viewer roles. Restrict access by team, tag, and data type.

Full audit trail

Every API call, login, and data change is logged and immutable. Exportable for compliance review.

Rate limiting & DDoS protection

Adaptive rate limiting at the API gateway with automated DDoS mitigation via Cloudflare.

Annual penetration testing

Independent penetration tests by Cobalt.io conducted every year. Reports available on request under NDA.

EU & US data residency

Choose where your data lives — EU (Frankfurt) or US (Virginia). Data never leaves your chosen region.

Responsible disclosure

Bug bounty programme

We take security vulnerabilities seriously and reward researchers who responsibly disclose issues. Our programme is managed through Intigriti.

Rewards range from £50 for low-severity findings to £10,000 for critical vulnerabilities. We respond to all valid reports within 48 hours.

In scope
  • crm.emacronai.com (production)
  • api.emacronai.com
  • Mobile apps (iOS & Android)
  • OAuth & authentication flows
[email protected]

Have security questions?

Our security team can provide SOC 2 reports, pen test summaries, and complete security questionnaires for enterprise procurement.