Security

Effective: March 28, 2026 Updated: March 28, 2026
SOC 2 Compliant
GDPR Ready
256-bit SSL

1. Infrastructure Security

ViralDashboard is built on enterprise-grade infrastructure, hosted on AWS with multi-region redundancy, network segmentation, and industry-leading physical security.

AWS Hosting

Primary in EU (Frankfurt) with failover in US East. Dedicated VPC, private subnets, and multi-AZ deployment for high availability.

Network Security

Cloudflare CDN and DDoS protection. Network segmentation isolates production, staging, and development environments.

Auto-Scaling

Dynamic capacity adjustment handles traffic spikes without degradation. Infrastructure scales with your needs.

2. Encryption

Your data is encrypted everywhere — in transit and at rest.

Data in Transit

  • TLS 1.3 enforced on all connections
  • HSTS with 1-year max-age and preloading
  • Forward secrecy and strong cipher suites

Data at Rest

  • AES-256 encryption for all databases and storage
  • AWS KMS with automatic key rotation
  • Encrypted backups in geographically separate regions

3. Access Controls & Compliance

Rigorous access controls and compliance standards protect your data at every level.

Control Details
MFA Required Multi-factor authentication required for all staff accessing production systems. SSO (SAML 2.0, OAuth 2.0) available for Enterprise.
Role-Based Access Granular RBAC with least-privilege principle. Quarterly access reviews, just-in-time elevated permissions, and 1-hour offboarding.
SOC 2 In Progress Actively working toward SOC 2 Type II certification (expected Q4 2026). Controls aligned with ISO 27001, GDPR, OWASP Top 10, and CIS Benchmarks.
Penetration Testing Annual third-party penetration tests. Weekly automated vulnerability scanning. SAST and DAST integrated into CI/CD pipeline.
Incident Response 24/7 monitoring with SIEM. 1-hour initial assessment. 72-hour customer notification for data breaches. Post-incident root cause analysis.
Business Continuity RPO: 1 hour. RTO: 4 hours. Daily automated backups with point-in-time recovery. Annual disaster recovery testing.

4. Responsible Disclosure Program

We value the work of security researchers and welcome reports of vulnerabilities.

How to Report

Email: security@viraldashboard.com

PGP Key available at viraldashboard.com/.well-known/security.txt

In Scope

  • viraldashboard.com and all subdomains
  • ViralDashboard API (api.viraldashboard.com)
  • ViralDashboard web and mobile applications

What We Offer

  • Acknowledgment within 2 business days
  • Regular updates on remediation progress
  • Credit in our security hall of fame
  • No legal action against researchers who follow guidelines

Remediation SLAs

Critical 24 hours
High 7 days
Medium 30 days
Low 90 days

5. Contact

Contact our security team for questions about our practices or to request security documentation (available to Enterprise customers under NDA).