Legal

Security

Last updated: June 28, 2026

Security is built into how we design, build, and operate every product.

Infrastructure

  • TLS 1.3 in transit, AES-256 at rest.
  • Audited cloud providers (AWS, Cloudflare, Vercel) with regional data residency on request.
  • Automated dependency scanning and weekly patch cadence.

Access

  • SSO + hardware-key 2FA for all team accounts.
  • Least-privilege access; production credentials rotated quarterly.
  • All client repos are private by default.

Application security

  • OWASP Top 10 review before every launch.
  • CSP, HSTS, X-Frame-Options, and Referrer-Policy headers configured at the edge.
  • Secrets in a managed vault — never in source control.

Compliance

We build to HIPAA, GDPR, and SOC 2 requirements on engagements that need them. Sub-processors and DPAs available on request.

Reporting a vulnerability

Email security@appdelivers.com. We aim to triage within 24 hours and patch critical issues within 7 days.

This page is a plain-language v1 draft and is being reviewed by counsel before launch. For specific legal questions, contact legal@appdelivers.com.