Legal
Security
Last updated: June 28, 2026
Security is built into how we design, build, and operate every product.
Infrastructure
- TLS 1.3 in transit, AES-256 at rest.
- Audited cloud providers (AWS, Cloudflare, Vercel) with regional data residency on request.
- Automated dependency scanning and weekly patch cadence.
Access
- SSO + hardware-key 2FA for all team accounts.
- Least-privilege access; production credentials rotated quarterly.
- All client repos are private by default.
Application security
- OWASP Top 10 review before every launch.
- CSP, HSTS, X-Frame-Options, and Referrer-Policy headers configured at the edge.
- Secrets in a managed vault — never in source control.
Compliance
We build to HIPAA, GDPR, and SOC 2 requirements on engagements that need them. Sub-processors and DPAs available on request.
Reporting a vulnerability
Email security@appdelivers.com. We aim to triage within 24 hours and patch critical issues within 7 days.
This page is a plain-language v1 draft and is being reviewed by counsel before launch. For specific legal questions, contact legal@appdelivers.com.
