Built for enterprise trust.
SupportEngine is architected with enterprise security requirements at its core. Every design decision considers security, privacy, and compliance.
Note on certifications
SupportEngine is building towards formal compliance certifications. We do not claim any certifications that have not been independently verified. Our security roadmap includes pursuing relevant certifications as the platform matures.
Security architecture
A layered approach to protecting your data and operations.
Data Protection
TLS 1.2+ Encryption in Transit
All data transmitted over TLS 1.2+. HSTS enforced. Certificates managed with automatic renewal.
AES-256 Encryption at Rest
All stored data encrypted using AES-256. Encryption keys managed separately from encrypted data.
Database-level Encryption
Sensitive fields encrypted at the database level in addition to storage-level encryption.
Access Control
Role-Based Access Control
Granular RBAC with custom roles and permission sets. Least-privilege access by default.
SSO-Ready Architecture
Architecture supports SAML 2.0 and OIDC integration with your existing identity provider.
MFA-Ready Architecture
Multi-factor authentication can be enforced at the organization level.
Session Management
Configurable session timeouts, concurrent session controls, and forced re-authentication.
Audit & Monitoring
Immutable Audit Logs
Every access, change, and administrative action logged with timestamp, actor, and IP address.
Security Monitoring
Continuous monitoring for suspicious patterns, anomalous access, and policy violations.
Login Audit
All authentication events — success, failure, IP change — are logged and available for review.
API Security
OAuth 2.0 Authentication
API access authenticated via OAuth 2.0 bearer tokens. Scoped permissions per application.
Rate Limiting
API rate limiting prevents abuse and protects service availability.
Input Validation
All API inputs validated and sanitized. SQL injection and XSS protection at every endpoint.
No Secrets in URLs
API keys and tokens are never exposed in URLs or log files.
Infrastructure
Multi-Tenant Data Isolation
Strict tenant data isolation at every infrastructure layer. Cross-tenant data access is architecturally prevented.
Backup Architecture
Regular automated backups with defined recovery point and time objectives.
Disaster Recovery Design
Platform designed with regional failover capability and defined recovery procedures.
Vulnerability Management
Dependency Auditing
Automated dependency vulnerability scanning in CI/CD pipeline.
Security Patching
Critical security patches applied promptly following defined SLA.
Responsible Disclosure
Security researchers can report vulnerabilities via our coordinated disclosure process.
Security vulnerability reporting
If you believe you have discovered a security vulnerability in SupportEngine, please contact us responsibly. We commit to acknowledging reports promptly and working to resolve validated issues.
Report a VulnerabilityReady to modernize your
IT service experience?
Bring requests, incidents, assets, knowledge and automation together with SupportEngine. 14-day free trial. No credit card required.
Questions? Talk to our team