Security
Last updated 11 August 2026
Placeholder text. This page is a structural template, not legal advice, and has not been reviewed by a solicitor. Replace it with policy drafted for your actual data practices before the site goes live.
Security work is mostly unglamorous and continuous. This page describes the controls we operate and how to reach us if you find a problem.
Certifications
- SOC 2 Type II, audited annually. Report available under NDA.
- ISO/IEC 27001 certified information security management system.
- UK GDPR and EU GDPR compliant, with a DPA available to all customers.
Encryption
Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Encryption keys are managed in a hardware security module and rotated annually. We do not support TLS versions below 1.2.
Access control
- SSO via SAML 2.0 and OIDC, with SCIM provisioning on Enterprise.
- Role-based permissions, down to row level in Analytics.
- Staff access to production requires hardware MFA, is granted just-in-time, and is logged.
- Customer-visible audit logs of authentication and admin actions.
Resilience
Backups run continuously with point-in-time recovery to any moment in the previous 35 days. We target a four-hour recovery time objective and a one-hour recovery point objective, and we test restores quarterly.
Testing
We commission an independent penetration test twice a year and run automated dependency and container scanning on every build. Summary reports are available to customers under NDA.
Incident response
We operate a documented incident response plan with 24/7 on-call. Where an incident affects your data we will notify you without undue delay and within 72 hours of becoming aware, with what we know at the time and updates as the picture firms up.
Reporting a vulnerability
Email security@adderbee.com with steps to reproduce. We acknowledge within one working day, and we will not pursue legal action against researchers who test in good faith, avoid privacy violations and service degradation, and give us reasonable time to fix the issue before disclosing it.