Security

Your Security,
Our Priority

Sectoria was built and tested by cybersecurity professionals. We practice what we preach.

Security Commitment

As a platform built for security teams, we understand that trust is earned, not given. We hold our infrastructure to the same uncompromising standards that our users demand for their own systems.

General Security Practices

Strong Authentication

Access to servers, source code, and third-party tools are secured with strong non-SMS two-factor authentication whenever possible. We allow you to do the same by supporting TOTP 2FA for Sectoria.

Password Security

Sectoria uses strong, randomly-generated passwords that are never re-used across systems or services.

Least Privilege Access

We don't normally hire contractors. If we did, they would be given the lowest level of access that would allow them to get their work done.

Secure Development Lifecycle

  • Continuous manual and automated security scans on all code and dependencies, ensuring vulnerabilities are identified and addressed at an early stage.
  • Proactive patching of vulnerable code and dependencies, keeping everything up-to-date with fixes released quickly.
  • Each release uses the latest version of underlying components: Operating System, Database Server, Web Server, Application Server, and Web Framework.
  • Every code change is independently reviewed and must pass security tests, with an emphasis on secure coding practices.

Data Sovereignty

  • Sectoria is a self-hosted solution—we don't have access to your data.
  • We do not store or process any of your confidential or sensitive information.
  • Your data stays on your infrastructure, under your control.

Infrastructure

  • Sectoria runs entirely in your own infrastructure.
  • Works on air-gapped networks—no internet connection required.
  • Full control over deployment, updates, and maintenance.

Encryption

At Rest

Full-Disk Encryption

The Sectoria VM is full-disk encrypted to protect data at rest.

In Transit

TLS/HTTPS Enforced

Sectoria enforces TLS (HTTPS) to protect all data transmitted to and from applications.

Application

AES-256-GCM

Sensitive data inside the application, such as OAuth tokens, is encrypted using AES-256-GCM encryption.

Passwords

Bcrypt Hashing

User passwords are securely hashed using industry-standard bcrypt. Sectoria never stores passwords or secrets as plain text.

Payment Security

Credit card and bank information is encrypted, stored, and processed by Stripe (not Sectoria) with AES-256 encryption.

  • We store only a transient token to reference customer credit cards through the Stripe API.
  • Credit cards are not stored on our servers—we never have access to card numbers or details.
  • All communication with Stripe is handled over an encrypted TLS connection.

Backups & Recovery

Since Sectoria is self-hosted and we don't have access to your data, backup and recovery procedures are your responsibility. We provide comprehensive documentation to help you set up robust backup strategies.

Frequently Asked Questions

What user data do you collect?

By default, none. We give users the option to share limited telemetry data to help us improve the product. More information can be found in our Privacy Notice.

Will you fill out our security questionnaire?

Due to our small team size, we do not have the bandwidth to fill out security questionnaires for customers on our off-the-shelf plans. Please email us if you do not see one of your specific questions answered on this page and we can add it.

Do you maintain security certifications such as SOC 2, ISO 27001, HIPAA or BAA?

While we'd eventually love to achieve these certifications, we don't hold them at this time. Please contact us if you'd like to discuss working with us to get these certifications.

How do I report a potential vulnerability or security concern?

Please contact us through our Contact page. If you have a discovery, please discreetly reach out to a member of the team for verification, vulnerability acceptance, and remediation timeline. We believe in—and participate in—responsible disclosure.

How often is Sectoria tested?

All of our users are security professionals and penetration testers. These users perform routine security assessments of the application as part of their corporate security initiatives.

Have Security Questions?

We're happy to discuss our security practices in more detail.

Contact Us