Security
1. Infrastructure Security
ViralDashboard is built on enterprise-grade infrastructure, hosted on AWS with multi-region redundancy, network segmentation, and industry-leading physical security.
AWS Hosting
Primary in EU (Frankfurt) with failover in US East. Dedicated VPC, private subnets, and multi-AZ deployment for high availability.
Network Security
Cloudflare CDN and DDoS protection. Network segmentation isolates production, staging, and development environments.
Auto-Scaling
Dynamic capacity adjustment handles traffic spikes without degradation. Infrastructure scales with your needs.
2. Encryption
Your data is encrypted everywhere — in transit and at rest.
Data in Transit
- TLS 1.3 enforced on all connections
- HSTS with 1-year max-age and preloading
- Forward secrecy and strong cipher suites
Data at Rest
- AES-256 encryption for all databases and storage
- AWS KMS with automatic key rotation
- Encrypted backups in geographically separate regions
3. Access Controls & Compliance
Rigorous access controls and compliance standards protect your data at every level.
| Control | Details |
|---|---|
| MFA Required | Multi-factor authentication required for all staff accessing production systems. SSO (SAML 2.0, OAuth 2.0) available for Enterprise. |
| Role-Based Access | Granular RBAC with least-privilege principle. Quarterly access reviews, just-in-time elevated permissions, and 1-hour offboarding. |
| SOC 2 In Progress | Actively working toward SOC 2 Type II certification (expected Q4 2026). Controls aligned with ISO 27001, GDPR, OWASP Top 10, and CIS Benchmarks. |
| Penetration Testing | Annual third-party penetration tests. Weekly automated vulnerability scanning. SAST and DAST integrated into CI/CD pipeline. |
| Incident Response | 24/7 monitoring with SIEM. 1-hour initial assessment. 72-hour customer notification for data breaches. Post-incident root cause analysis. |
| Business Continuity | RPO: 1 hour. RTO: 4 hours. Daily automated backups with point-in-time recovery. Annual disaster recovery testing. |
4. Responsible Disclosure Program
We value the work of security researchers and welcome reports of vulnerabilities.
How to Report
Email: security@viraldashboard.com
PGP Key available at viraldashboard.com/.well-known/security.txt
In Scope
- viraldashboard.com and all subdomains
- ViralDashboard API (api.viraldashboard.com)
- ViralDashboard web and mobile applications
What We Offer
- Acknowledgment within 2 business days
- Regular updates on remediation progress
- Credit in our security hall of fame
- No legal action against researchers who follow guidelines
Remediation SLAs
5. Contact
Contact our security team for questions about our practices or to request security documentation (available to Enterprise customers under NDA).
Security Team
security@viraldashboard.com