Our Security

Seroscale as a company has been built to protect our customers data, and is focused on security, privacy, and high availability.

We chose to host our platform within AWS (Amazon Web Services) due to its focus around security, redundancy, resilience, flexibility and scalability. With AWS, even we do not have access to the datacenter.

We protect your data

Seroscale strives to provide best in class service for our customers. Achieving this goal depends on ensuring our software is a secure and trustworthy platform for storing data and making it accessible 24/7/365.

We operate a "zero knowledge" policy. This means our platform can only access your data from an authorized access token that you (your account) provide from the app.

Your data is sent using HTTPS

Whenever your data are in transit between you and us, everything is encrypted, and sent using HTTPS through port 443.

Your data is encrypted at rest

Once data arrives at AWS, they are encrypted at rest in separate S3 storage buckes using the industry-standard AES 256-bit encryption algorithm. AWS securely stores and manages Seroscale's encryption keys. This ensures that even if an intruder were to gain access to the physical storage devices, the data would remain encrypted and indecipherable without the appropriate decryption keys, rendering the information useless.

We use secure infrastructure

Seroscale uses AWS in Ohio, United States to store user data. These servers undergo recurring assessments to ensure compliance with the latest industry standards and continually manage risk. By using AWS as our data center, our infrastructure is accredited by most common certifications and laws:

  • ISO 9001
  • ISO 27001
  • ISO 27017
  • SOC 1
  • SOC 2
  • SOC 3
  • PCI DSS
  • HIPPA
  • HDS
  • FIPS
  • NIST
  • EU GDPR
  • UK Cyber Essentials Plus

All AWS data centers feature the following security measures:

  • AWS employee only access
  • 24-hour CCTV monitoring
  • Intrusion detection
  • Full access review and logging
  • Fully redundant electrical power systems, with a backup power supply to remain operational
  • Automatic fire detection and suppression systems
  • Leakage detection systems to detect the presence of water