TLS 1.3 in transit. AES-256 at rest. Customer payloads encrypted with per-tenant keys, rotated quarterly.
SSO + SCIM on Unlimited. Role-based scopes on every API key. All employee access requires hardware MFA.
Every webhook send, key issuance, and configuration change is logged for 12 months and exportable on Unlimited.
Tenants are logically isolated at the database row level with policy enforcement and at the application layer with scoped credentials.
Continuous WAL backups across two regions. RPO 5 minutes, RTO 60 minutes. Restore drills run quarterly.
Every sub-processor undergoes annual security review. Current list available on request via security@pixelyeah.com.
Where we are.
- SHIPPEDGDPR + CCPA compliant
- SHIPPEDHIPAA-eligible infrastructure
- IN PROGRESS · Q4 2026SOC 2 Type II audit
- IN PROGRESS · Q1 2027ISO 27001
Found something?
Email security@pixelyeah.com with reproduction steps. We acknowledge within one business day and pay bounties on validated reports.
Available on request — security@pixelyeah.com
-----END PGP PUBLIC KEY BLOCK-----