Built for enterprise trust.

SupportEngine is architected with enterprise security requirements at its core. Every design decision considers security, privacy, and compliance.

Note on certifications

SupportEngine is building towards formal compliance certifications. We do not claim any certifications that have not been independently verified. Our security roadmap includes pursuing relevant certifications as the platform matures.

Security architecture

A layered approach to protecting your data and operations.

Data Protection

TLS 1.2+ Encryption in Transit

All data transmitted over TLS 1.2+. HSTS enforced. Certificates managed with automatic renewal.

AES-256 Encryption at Rest

All stored data encrypted using AES-256. Encryption keys managed separately from encrypted data.

Database-level Encryption

Sensitive fields encrypted at the database level in addition to storage-level encryption.

Access Control

Role-Based Access Control

Granular RBAC with custom roles and permission sets. Least-privilege access by default.

SSO-Ready Architecture

Architecture supports SAML 2.0 and OIDC integration with your existing identity provider.

MFA-Ready Architecture

Multi-factor authentication can be enforced at the organization level.

Session Management

Configurable session timeouts, concurrent session controls, and forced re-authentication.

Audit & Monitoring

Immutable Audit Logs

Every access, change, and administrative action logged with timestamp, actor, and IP address.

Security Monitoring

Continuous monitoring for suspicious patterns, anomalous access, and policy violations.

Login Audit

All authentication events — success, failure, IP change — are logged and available for review.

API Security

OAuth 2.0 Authentication

API access authenticated via OAuth 2.0 bearer tokens. Scoped permissions per application.

Rate Limiting

API rate limiting prevents abuse and protects service availability.

Input Validation

All API inputs validated and sanitized. SQL injection and XSS protection at every endpoint.

No Secrets in URLs

API keys and tokens are never exposed in URLs or log files.

Infrastructure

Multi-Tenant Data Isolation

Strict tenant data isolation at every infrastructure layer. Cross-tenant data access is architecturally prevented.

Backup Architecture

Regular automated backups with defined recovery point and time objectives.

Disaster Recovery Design

Platform designed with regional failover capability and defined recovery procedures.

Vulnerability Management

Dependency Auditing

Automated dependency vulnerability scanning in CI/CD pipeline.

Security Patching

Critical security patches applied promptly following defined SLA.

Responsible Disclosure

Security researchers can report vulnerabilities via our coordinated disclosure process.

Security vulnerability reporting

If you believe you have discovered a security vulnerability in SupportEngine, please contact us responsibly. We commit to acknowledging reports promptly and working to resolve validated issues.

Report a Vulnerability
Get Started Today

Ready to modernize your
IT service experience?

Bring requests, incidents, assets, knowledge and automation together with SupportEngine. 14-day free trial. No credit card required.

Questions? Talk to our team