Security & Compliance

Your security questions answered. Learn how we protect your data and maintain compliance.

Security Whitepaper

Download our comprehensive security documentation.

View & Download PDF

Report Security Issue

Found a security vulnerability? Report it to our security team.

Contact Security

Request BAA

Healthcare customers can request a Business Associate Agreement.

Request BAA

Data Security

Where is my data stored?

All data is stored in Google Cloud Platform (GCP) data centers located in the United States. We use GCP's enterprise-grade infrastructure with SOC 2 Type II certification.

Is my data encrypted?

Yes. All data is encrypted both in transit (TLS 1.3) and at rest (AES-256). Encryption is handled automatically by Google Cloud Platform.

Who can access my data?

Only authorized users from your organization can access your data. We use multi-tenant isolation to ensure complete data separation between organizations.

How do you handle backups?

We perform automated daily backups with 90-day retention. Backups are encrypted and stored in separate GCP regions for disaster recovery.

Compliance & Certifications

Do you have SOC 2 certification?

Our infrastructure is built on Google Cloud Platform, which maintains SOC 2 Type II certification. We inherit many security controls from GCP. We are working toward our own SOC 2 Type II certification and will update this page when available.

Are you HIPAA compliant?

We offer Business Associate Agreements (BAA) for healthcare customers handling PHI. Contact us at info@netcloudshield.com to request a BAA.

Do you comply with GDPR?

Yes. We comply with GDPR requirements including data subject rights, data processing agreements, and data breach notification procedures. See our Privacy Policy for details.

What about other compliance standards?

We follow industry best practices and are continuously working toward additional certifications. Contact us to discuss specific compliance requirements.

Access Control

How do you authenticate users?

We use Firebase Authentication with support for email/password and Google OAuth. We follow industry best practices for secure authentication.

How is data isolated between organizations?

We use a multi-tenant architecture with strict tenant isolation. Each organization's data is stored in separate Firestore collections, and access is controlled by tenant_id in authentication tokens.

Can I control who has access to my data?

Yes. As a tenant owner, you can manage user access through the admin dashboard. You can add/remove users and assign roles.

What about API access?

API access is controlled through API keys that are scoped to your tenant. You can create, revoke, and manage API keys from the Settings page.

Infrastructure

What cloud provider do you use?

We use Google Cloud Platform (GCP) for all infrastructure. GCP maintains SOC 2 Type II, ISO 27001, and other certifications.

Where are your servers located?

All servers are located in Google Cloud Platform data centers in the United States. We do not store data outside the US unless specifically requested.

What is your uptime SLA?

We target 99.9% uptime. Our infrastructure uses auto-scaling and redundancy to ensure high availability.

How do you handle security incidents?

We have a documented incident response plan. In the event of a security incident, we will notify affected customers within 24 hours. Contact info@netcloudshield.com to report security issues.