Home/Security
SecurityWe hold ourselves to the standard we sell.
Grandeza handles consent records, call and message logs, and the audit trail our clients rely on in a dispute. That data is evidence. This page documents how we protect it — encryption, our internal review process, where our security program stands today, and how to tell us if we've got something wrong. We'd rather be accurate here than impressive.
Last updated: August 2026 · Reviewed quarterly
Encrypted at rest. Encrypted in transit. No exceptions.
AES-256, enforced at the storage layer
Every store that touches client data is encrypted at rest with AES-256 — primary databases, object storage, backups and point-in-time snapshots. Because it is enforced at the storage layer rather than per-application, there is no code path that can write an unencrypted copy.
TLS 1.2+ everywhere, HSTS preloaded
All traffic to and from Grandeza is served over TLS 1.2 or higher. HTTP is redirected, never served. HSTS is set with includeSubDomains and preload, so browsers refuse an unencrypted connection before one is ever attempted.
Managed keys, rotated on schedule
Encryption keys are held in a managed key service, never in application code or configuration files. Keys are rotated on a fixed schedule and on any suspected exposure. No engineer holds a standing copy of a production key.
Least privilege, MFA required, logged
Production access is role-based and granted on the principle of least privilege. Multi-factor authentication is required policy for every account with production reach, and we're in the process of confirming full enforcement across every system as we formalize this program. Access is time-bound and every session is logged to an append-only audit trail.
Thirteen layers we check ourselves against.
We hold our own stack to the same standard we sell — thirteen layers, each with a defined pass condition. Today this review is manual before major releases; we're building it into an automated CI gate so a failing layer blocks a release as a matter of process, not memory.
Network perimeter
Edge firewall rules, DDoS mitigation and rate limiting reviewed against the current threat profile.
Transport security
TLS configuration, cipher suites, certificate validity and HSTS enforcement verified end to end.
Authentication
Credential handling, MFA enforcement, session lifetime and lockout behaviour reviewed for bypass risk.
Authorization
Role boundaries and object-level permissions checked for horizontal and vertical privilege escalation.
Input handling
Injection, deserialization and traversal surfaces reviewed across request paths that accept user input.
Output encoding
Cross-site scripting and content-injection vectors checked, with a Content Security Policy in place.
Data at rest
Encryption coverage confirmed across primary stores, replicas, backups and snapshots — no unencrypted copies.
Secrets management
Repositories, images and configuration checked for committed credentials, tokens and private keys.
Dependencies
Dependency tree reviewed against known-vulnerability databases; automated scanning is on our near-term roadmap.
Logging & audit trail
Security-relevant events captured and written to a tamper-evident, append-only log.
Backup & recovery
Backup coverage confirmed across primary data stores as part of our review process.
Third-party surface
Every sub-processor and integration reviewed for the data it receives and the access it holds.
Configuration drift
Running production checked against declared infrastructure state as part of our review process.
Not yet on the calendar — here's where we actually are.
We haven't commissioned an independent penetration test yet. Rather than let this page get ahead of the actual program, here's what's actually in place today and what's committed next.
Independent third-party test — not yet run
We have not yet commissioned an independent penetration test. As Grandeza takes on more client data, a full-scope test by an independent security firm is a committed near-term milestone — not a completed one. We'll update this page the day it happens.
Manual review before material changes
Until a formal testing program is in place, material changes to authentication, data storage or the intake pipeline get a manual security review by the team before shipping — not an independent retest, but not nothing either.
Automated scanning — on the roadmap
Automated dependency and secret scanning is on our near-term roadmap, tied to the CI gate we're actively building. Today, dependency updates and code changes are reviewed manually before merge.
Remediation windows — not yet formally tracked
We don't yet have automatically enforced remediation SLAs. Our working target, once formal vulnerability tracking is in place: critical findings within 7 days, high within 30, medium within 90. Today, findings are fixed as they're found rather than tracked against a formal clock.
Clients under an active engagement can request our current security roadmap and target dates under NDA.
We're formalizing a written incident response plan.
A documented, rehearsed plan is the goal — we're not there yet. Here are the principles we commit to following if something goes wrong today, while we finish writing the formal version.
Detect & declare
Anyone on the team can and will raise a suspected incident immediately; nobody has to seek permission first.
Contain
Containment takes priority over root cause. Credentials get rotated, affected access revoked, and the blast radius bounded before investigation continues.
Assess & notify
Scope and data exposure get established. Affected clients are notified without undue delay, with regulatory notification timelines treated as a ceiling, not a target.
Eradicate & recover
Root cause gets removed and service restored from a known-good state, with integrity verified before traffic returns.
Post-incident review
A blameless review follows, producing corrective actions with named owners and due dates.
Tabletop exercise
Once the written plan exists, we'll rehearse it on a recurring basis and track gaps like production findings. That rehearsal hasn't started yet.
Found something? Tell us.
We would rather hear it from you than from a claimant. If you believe you have found a vulnerability in a Grandeza system, report it and we will work it with you.
security@grandeza.io
Use this address for security reports only. For privacy requests use privacy@grandeza.io; for anything else, hello@grandeza.io.
What to include
- The affected asset — domain, endpoint or feature.
- Clear reproduction steps, and a proof of concept if you have one.
- The impact you believe it has, and any prerequisites an attacker would need.
- How you would like to be credited, if the finding is confirmed.
What we commit to
- Acknowledgement within 1 business day that a human has your report.
- Triage assessment within 5 business days, including whether we accept the finding.
- Progress updates until the issue is closed, and credit on request once it is fixed.
- No legal action against good-faith research that follows the rules below.
Safe harbour & ground rules
We will not pursue legal action against researchers who act in good faith and stay inside these boundaries. Testing that breaks them falls outside safe harbour.
- Do not access, modify or exfiltrate data that is not yours. If you encounter client data, stop and tell us immediately.
- Do not degrade service — no denial-of-service, no load or stress testing, no automated scanning that generates disruptive volume.
- Do not use social engineering, physical intrusion, or attacks against our staff, vendors or offices.
- Give us reasonable time to fix before any public disclosure, and coordinate the timing with us.
- Stay within our own systems. Third-party services we use are out of scope; report those to their owners.
Grandeza does not currently operate a paid bug bounty. We do credit confirmed reporters, with their permission, once a fix has shipped.
Want this standard applied to your intake?
The free scan grades your live SMS, call and web intake across all 18 controls and returns one score — plus your top three exposures, ranked by cost.
Get your Grandeza Score