Last updated July 20, 2026
All data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Sensitive credentials are stored in a dedicated secrets manager, never in application logs.
We enforce least-privilege access internally, require MFA for all staff, and log administrative actions. Enterprise customers can enable SSO and receive detailed audit logs.
Attestly runs on hardened cloud infrastructure with isolated environments, automated patching, and continuous monitoring. Backups are encrypted and tested on a regular schedule.
Each customer's data is logically isolated and scoped to their account. Questionnaire responses are never used to train shared models or exposed to other customers.
We welcome security researchers. If you believe you have found a vulnerability, contact security@attestly.com and we will acknowledge and investigate promptly.