Enterprise-Grade Security

Security You Can Trust

TIDALBAY is built with security at its core. We protect your data with the same rigor we help you protect your employees.

SOC 2 Type II
AICPA
ISO 27001
ISO
GDPR Compliant
EU
CCPA Compliant
State of California
HIPAA Compliant
HHS

Data Encryption

Your data is protected with industry-leading encryption standards

Encryption at Rest

All data encrypted using AES-256 encryption with customer-managed keys (BYOK) available.

Encryption in Transit

TLS 1.3 for all data in transit with certificate pinning for mobile applications.

Field-Level Encryption

Sensitive PII fields are individually encrypted for additional protection.

Access Control

Granular controls to ensure only authorized access

Multi-Factor Authentication

MFA required for all administrative access with support for hardware security keys.

Single Sign-On

SAML 2.0 and OIDC SSO integration with all major identity providers.

Role-Based Access Control

Granular permissions with principle of least privilege enforced at every level.

IP Allowlisting

Restrict access to your TIDALBAY tenant from approved IP addresses only.

Infrastructure Security

Enterprise-grade infrastructure with high availability

Multi-Region Deployment

Data residency options with deployments in US, EU, and APAC regions.

99.99% SLA

Enterprise SLA with multi-AZ deployment and automatic failover.

Tenant Isolation

Complete data isolation between tenants with dedicated database instances.

Continuous Backup

Point-in-time recovery with 35-day retention and cross-region replication.

Audit & Monitoring

Complete visibility and accountability for all actions

Immutable Audit Logs

Complete audit trail of all actions with tamper-proof logging.

SIEM Integration

Export security logs to your SIEM for centralized monitoring.

Regular Penetration Testing

Quarterly penetration tests by third-party security firms.

Vulnerability Management

Continuous vulnerability scanning with SLA-based remediation.

Compliance & Certifications

TIDALBAY meets the most stringent compliance requirements

SOC 2 Type II

Annual SOC 2 Type II audits covering Security, Availability, and Confidentiality.

GDPR Compliance

Full GDPR compliance with data residency options and right-to-deletion support.

HIPAA Compliance

BAA available for healthcare customers with HIPAA-compliant data handling.

CCPA Compliance

California Consumer Privacy Act compliance with data access and deletion support.

Security Documentation

Request access to our security documentation and compliance reports

SOC 2 Type II Report

Annual third-party audit report covering Trust Services Criteria.

Request AccessRequires NDA

Penetration Test Summary

Executive summary of most recent third-party penetration test.

Request AccessRequires NDA

Security Whitepaper

Detailed overview of TIDALBAY security architecture and controls.

Data Processing Agreement

Standard DPA for GDPR compliance.

Business Associate Agreement

Standard BAA for HIPAA-covered entities.

Have Security Questions?

Our security team is available to answer your questions and provide documentation for your security review process.