Skip to main content
Security at OfferlyIQ

Your data is safe with us

Security is not an add-on feature — it's built into every layer of OfferlyIQ. Here's how we protect your data, your sessions, and your privacy.

TLS 1.3 AES-256 GDPR CCPA SOC 2

How We Protect You

Security by Design

Every layer of our stack — from your browser to our database — is built with security as a first-class requirement.

Encryption in Transit & at Rest

All data is encrypted with TLS 1.3 in transit. Session recordings, transcripts, and personal data are encrypted at rest using AES-256.

Minimal Data Collection

We collect only what's necessary to deliver the product. Audio processed by Live Assist is not retained after your session ends by default.

Secure Authentication

Passwords are hashed with bcrypt. We support OAuth 2.0 (Google, Apple, LinkedIn). Session tokens rotate on each login and expire on logout.

Infrastructure Security

Hosted on SOC 2 Type II certified infrastructure. Network segmentation, firewalls, and intrusion detection systems are in place.

Access Controls

Employee access to production systems follows the principle of least privilege. All access is logged and reviewed quarterly.

Regular Audits & Patching

Dependencies are scanned automatically for known CVEs. Security patches are applied within 24 hours of disclosure for critical vulnerabilities.

Standards & Compliance

Built to Meet Global Standards

GDPRCompliant

EU data protection regulation compliance

CCPACompliant

California Consumer Privacy Act compliance

SOC 2 Type IICompliant

Infrastructure hosted on SOC 2 certified platforms

TLS 1.3Enforced

Latest transport layer security protocol

AES-256Enforced

Industry-standard encryption at rest

OWASP Top 10Reviewed

Annual review against common web vulnerabilities

Infrastructure

What Runs Under the Hood

Cloud Infrastructure

  • Hosted on SOC 2 Type II certified cloud providers
  • Multi-region redundancy for high availability
  • Automatic DDoS mitigation at the network edge
  • Isolated VPC with strict network ACLs

Data Storage

  • AES-256 encryption at rest for all databases
  • Automated daily backups with point-in-time recovery
  • Production databases are never directly accessible from the internet
  • Personal data and audio stored in separate isolated buckets

Application Security

  • Automated dependency scanning for CVEs (daily)
  • Content Security Policy (CSP) headers on all pages
  • CSRF protection on all state-changing endpoints
  • Rate limiting and bot detection on auth endpoints

Monitoring & Incident Response

  • 24/7 automated anomaly detection and alerting
  • Immutable audit logs for all privileged actions
  • Incident response playbooks reviewed quarterly
  • RTO < 4 hours for critical security incidents
Found a Vulnerability?

Responsible Disclosure

We genuinely appreciate security researchers who help us keep OfferlyIQ safe. If you've found a vulnerability, please report it privately so we can fix it before it affects users.

01

Email us

Send details to security@offerlyiq.ai — include steps to reproduce, impact, and any proof of concept.

02

We acknowledge

You'll receive a confirmation within 24 hours and a case number to track the report.

03

We investigate

Our security team investigates, triages severity, and begins remediation. We'll keep you updated.

04

We fix & credit

Once resolved, we'll notify you and — with your permission — credit you in our security acknowledgements.

Ground Rules

Do not access or modify other users' data
Do not perform DoS/DDoS attacks on our infrastructure
Do not use automated scanners without prior approval
Do not publicly disclose before we've had a chance to fix it
We will not pursue legal action against good-faith reporters
We credit researchers in our acknowledgements (with consent)

Questions about security?

Our security team responds to all enquiries within 24 hours. For non-security support, contact our general support team.