Data protection
All data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Secrets and keys are managed in a dedicated key-management service with strict rotation policies. We minimize the personal data we handle and never require personally identifying end-user fields to operate.
Access control
Access to production systems follows least-privilege principles, is gated behind SSO with hardware-backed MFA, and is logged and reviewed. Engineers receive access only to the systems their role requires, and access is revoked promptly on role change or departure.
Infrastructure
Belfort runs on hardened cloud infrastructure across multiple availability zones, with network segmentation, automated patching, continuous vulnerability scanning, and daily encrypted backups tested for restoration.
Development practices
Every change is peer-reviewed and passes automated security checks before deploy. We run regular third-party penetration tests and maintain a formal incident-response plan with defined severities and on-call rotation.
Compliance
We maintain SOC 2 Type II and support GDPR and UK GDPR compliance through our Data Processing Addendum. Our SOC 2 report is available under NDA to customers and prospects on request.