SOC 2 Type II
TowerVue is pursuing SOC 2 Type II certification under the Trust Services Criteria for Security, Availability, and Confidentiality. The audit window opened June 22, 2026. Evidence is collected daily, automatically, and recorded in a hash-chained ledger that cannot be retroactively altered.
To request a copy of our report or security documentation, contact security@towervue.app
Core architecture
Isolation
Every TowerVue customer runs on a physically dedicated database. There is no multi-tenant database where a misconfiguration could expose your rows to another customer. Isolation is not a configuration flag — it is structural. An automated probe writes a unique canary record to one customer's database every day and verifies it does not appear in any other. The result is recorded as cryptographically verifiable evidence.
What we control and how
Every customer operates on a physically dedicated database. Your data has never shared infrastructure with another customer — proven by an automated daily canary test that verifies isolation at both the storage and routing layers.
Access to TowerVue systems is provisioned through a documented process. Every grant is logged in our append-only compliance ledger. Quarterly access reviews ensure the list stays current.
When a user is deactivated, all active sessions and refresh tokens are invalidated in the same transaction. There is no window between deactivation and lockout.
Our dependency vulnerability inventory is ingested automatically from GitHub Dependabot and verified weekly. Remediation SLAs: Critical 7 days, High 30 days, Medium 90 days.
Authentication failures, administrative actions, and impersonation events are captured in real time and forwarded to the compliance ledger. Nothing is retroactively editable.
Security incidents are tracked through a structured incident register. Affected customers are notified within 72 hours of discovery. Annual tabletop exercises keep the response process current.
All production code changes flow through GitHub with peer review. Our change-attestation webhook captures every merge to the main branch as a timestamped compliance event.
Third-party service providers — infrastructure, email, monitoring — are assessed quarterly for security posture. The current vendor inventory is maintained in our compliance record.
Point-in-time recovery bookmarks are pulled from our database infrastructure weekly and stored as evidence. Quarterly restore drills verify that recovery actually works — not just that the backup job ran.
Customers can request a full data export at any time. On offboarding, data is exported and then deleted within 30 days. The full process is logged and auditable.
Security questions or report requests
We respond to security inquiries within one business day.