Security and compliance

Encryption

TLS in transit. Encrypted storage at rest in production. Session cookies are HTTP-only.

Isolation

One AWS account ID per tenant. Queries always scoped by tenant_id.

Audit logging

Login, entitlement, metering, and admin events retained ≥ 1 year.

Incidents

Report to security@bestsaas.example. We notify impacted customers of relevant incidents.

Data deletion

Customer data is deleted on request or when no longer needed under the EULA, within 30 days.

No malware

Releases are scanned before Marketplace publication. Known CVEs are patched promptly.