Security
Scalix takes security seriously. Here's how we protect your data and infrastructure.
Encryption
- TLS 1.2+ for all data in transit - AES-256-GCM envelope encryption for secrets, credentials, and private keys - Encrypted off-site backups (nightly) - API keys are stored hashed, never in plaintext
Infrastructure
- Deployed on dedicated servers in the EU - Dedicated micro-VM isolation for serverless functions and app runtimes - Per-tenant database isolation (isolated database and role per tenant) - Per-workload network isolation between tenants
Authentication
- Multi-factor authentication (TOTP) available - API key scoping with granular permissions - JWT session management with configurable TTL
Database Security
- Query firewall to help mitigate SQL injection - Connection pooling with per-tenant isolation - Point-in-time recovery for data protection
Compliance
- Designed to meet GDPR (EU) requirements - Designed to meet India DPDP Act requirements - EU data hosting; additional regions planned for sovereignty requirements
Incident Response
We maintain a security incident response plan. Report vulnerabilities to security@scalix.world.
SOC 2
SOC 2 Type II certification is on our roadmap.