Home/Security

Security

We hold ourselves to the standard we sell.

Grandeza handles consent records, call and message logs, and the audit trail our clients rely on in a dispute. That data is evidence. This page documents how we protect it — encryption, our internal review process, where our security program stands today, and how to tell us if we've got something wrong. We'd rather be accurate here than impressive.

Last updated: August 2026 · Reviewed quarterly

01 · Data protection

Encrypted at rest. Encrypted in transit. No exceptions.

At rest

AES-256, enforced at the storage layer

Every store that touches client data is encrypted at rest with AES-256 — primary databases, object storage, backups and point-in-time snapshots. Because it is enforced at the storage layer rather than per-application, there is no code path that can write an unencrypted copy.

In transit

TLS 1.2+ everywhere, HSTS preloaded

All traffic to and from Grandeza is served over TLS 1.2 or higher. HTTP is redirected, never served. HSTS is set with includeSubDomains and preload, so browsers refuse an unencrypted connection before one is ever attempted.

Key management

Managed keys, rotated on schedule

Encryption keys are held in a managed key service, never in application code or configuration files. Keys are rotated on a fixed schedule and on any suspected exposure. No engineer holds a standing copy of a production key.

Access

Least privilege, MFA required, logged

Production access is role-based and granted on the principle of least privilege. Multi-factor authentication is required policy for every account with production reach, and we're in the process of confirming full enforcement across every system as we formalize this program. Access is time-bound and every session is logged to an append-only audit trail.

02 · Production review

Thirteen layers we check ourselves against.

We hold our own stack to the same standard we sell — thirteen layers, each with a defined pass condition. Today this review is manual before major releases; we're building it into an automated CI gate so a failing layer blocks a release as a matter of process, not memory.

01

Network perimeter

Edge firewall rules, DDoS mitigation and rate limiting reviewed against the current threat profile.

02

Transport security

TLS configuration, cipher suites, certificate validity and HSTS enforcement verified end to end.

03

Authentication

Credential handling, MFA enforcement, session lifetime and lockout behaviour reviewed for bypass risk.

04

Authorization

Role boundaries and object-level permissions checked for horizontal and vertical privilege escalation.

05

Input handling

Injection, deserialization and traversal surfaces reviewed across request paths that accept user input.

06

Output encoding

Cross-site scripting and content-injection vectors checked, with a Content Security Policy in place.

07

Data at rest

Encryption coverage confirmed across primary stores, replicas, backups and snapshots — no unencrypted copies.

08

Secrets management

Repositories, images and configuration checked for committed credentials, tokens and private keys.

09

Dependencies

Dependency tree reviewed against known-vulnerability databases; automated scanning is on our near-term roadmap.

10

Logging & audit trail

Security-relevant events captured and written to a tamper-evident, append-only log.

11

Backup & recovery

Backup coverage confirmed across primary data stores as part of our review process.

12

Third-party surface

Every sub-processor and integration reviewed for the data it receives and the access it holds.

13

Configuration drift

Running production checked against declared infrastructure state as part of our review process.

03 · Penetration testing

Not yet on the calendar — here's where we actually are.

We haven't commissioned an independent penetration test yet. Rather than let this page get ahead of the actual program, here's what's actually in place today and what's committed next.

Planned

Independent third-party test — not yet run

We have not yet commissioned an independent penetration test. As Grandeza takes on more client data, a full-scope test by an independent security firm is a committed near-term milestone — not a completed one. We'll update this page the day it happens.

Today

Manual review before material changes

Until a formal testing program is in place, material changes to authentication, data storage or the intake pipeline get a manual security review by the team before shipping — not an independent retest, but not nothing either.

Building now

Automated scanning — on the roadmap

Automated dependency and secret scanning is on our near-term roadmap, tied to the CI gate we're actively building. Today, dependency updates and code changes are reviewed manually before merge.

Our target

Remediation windows — not yet formally tracked

We don't yet have automatically enforced remediation SLAs. Our working target, once formal vulnerability tracking is in place: critical findings within 7 days, high within 30, medium within 90. Today, findings are fixed as they're found rather than tracked against a formal clock.

Clients under an active engagement can request our current security roadmap and target dates under NDA.

04 · Incident response

We're formalizing a written incident response plan.

A documented, rehearsed plan is the goal — we're not there yet. Here are the principles we commit to following if something goes wrong today, while we finish writing the formal version.

Step 01

Detect & declare

Anyone on the team can and will raise a suspected incident immediately; nobody has to seek permission first.

Step 02

Contain

Containment takes priority over root cause. Credentials get rotated, affected access revoked, and the blast radius bounded before investigation continues.

Step 03

Assess & notify

Scope and data exposure get established. Affected clients are notified without undue delay, with regulatory notification timelines treated as a ceiling, not a target.

Step 04

Eradicate & recover

Root cause gets removed and service restored from a known-good state, with integrity verified before traffic returns.

Step 05

Post-incident review

A blameless review follows, producing corrective actions with named owners and due dates.

Not started yet

Tabletop exercise

Once the written plan exists, we'll rehearse it on a recurring basis and track gaps like production findings. That rehearsal hasn't started yet.

05 · Coordinated disclosure

Found something? Tell us.

We would rather hear it from you than from a claimant. If you believe you have found a vulnerability in a Grandeza system, report it and we will work it with you.

Report to

security@grandeza.io

Use this address for security reports only. For privacy requests use privacy@grandeza.io; for anything else, hello@grandeza.io.

Report a vulnerability

What to include

  • The affected asset — domain, endpoint or feature.
  • Clear reproduction steps, and a proof of concept if you have one.
  • The impact you believe it has, and any prerequisites an attacker would need.
  • How you would like to be credited, if the finding is confirmed.

What we commit to

  • Acknowledgement within 1 business day that a human has your report.
  • Triage assessment within 5 business days, including whether we accept the finding.
  • Progress updates until the issue is closed, and credit on request once it is fixed.
  • No legal action against good-faith research that follows the rules below.

Safe harbour & ground rules

We will not pursue legal action against researchers who act in good faith and stay inside these boundaries. Testing that breaks them falls outside safe harbour.

  • Do not access, modify or exfiltrate data that is not yours. If you encounter client data, stop and tell us immediately.
  • Do not degrade service — no denial-of-service, no load or stress testing, no automated scanning that generates disruptive volume.
  • Do not use social engineering, physical intrusion, or attacks against our staff, vendors or offices.
  • Give us reasonable time to fix before any public disclosure, and coordinate the timing with us.
  • Stay within our own systems. Third-party services we use are out of scope; report those to their owners.

Grandeza does not currently operate a paid bug bounty. We do credit confirmed reporters, with their permission, once a fix has shipped.

Free · 3 minutes · No obligation

Want this standard applied to your intake?

The free scan grades your live SMS, call and web intake across all 18 controls and returns one score — plus your top three exposures, ranked by cost.

Get your Grandeza Score