Security
Security at FalconCloud™
Last reviewed 2026-07-26.
Encryption
Credentials are encrypted at rest with AES-256-GCM. The master key is held in a secure edge secret store; per-stack keys are derived via HMAC-SHA256(master, stack_id). Compromising one stack does not expose others.
Audit log integrity
Every action is recorded in an append-only log with a SHA-256 hash chain. Historical row modification is detectable. Logs export to JSON or CSV for SOC 2 evidence packs.
RBAC
Roles live in dedicated
user_roles and user_platform_role tables, never on user profiles. Per-org roles cascade to tenant-level roles. Sub-processors
The full list of third parties that handle customer data is at /legal/sub-processors.
Transport & headers
TLS 1.3 enforced. HSTS preload. CSP, X-Frame-Options, and Referrer-Policy set on every response.
Responsible disclosure
Email security@falconveritas.com. Acknowledged within 24 hours, triage within 72 hours.
Compliance status
- SOC 2 Type II — audit in progress, evidence pack available under NDA.
- GDPR Art. 30 record of processing — see sub-processors.
- Self-hosted by default — your data never touches our servers unless you opt in.