Available on request
What we can send you
Email security@towervue.app — we respond within one business day.
- —Completed CAIQ v4 or SIG Lite response
- —SOC 2 Type II evidence package for the current audit window, with chain verification
- —Data Processing Agreement and subprocessor register
- —Information Security Policy, Access Control Policy, Incident Response Plan
- —Architecture and data flow documentation
Do you hold SOC 2, ISO 27001, or other certifications?
TowerVue's SOC 2 Type II audit window opened June 22, 2026, covering Security, Availability, and Confidentiality. The report has not yet been issued. We do not currently hold ISO 27001, HIPAA, PCI DSS, or FedRAMP authorization.
How is compliance evidence collected?
Automated monitors emit evidence continuously into an append-only, hash-chained ledger — isolation proofs daily, backup verification and vulnerability scans weekly, access and vendor reviews quarterly. Chain integrity is independently verifiable and the full evidence package is exportable by audit window.
Do you maintain a risk register?
Yes. A documented risk register is reviewed annually against likelihood and impact, with mitigating controls mapped to each entry.
Do you support SSO?
Yes — SSO via OpenID Connect, SP-initiated, against your identity provider. Native SAML is not implemented.
Do you support automated provisioning?
Yes — SCIM 2.0 for automated provisioning and deprovisioning — removal from your directory revokes TowerVue access in the same event.
Is MFA available and enforceable?
Yes — MFA via TOTP, enforceable platform-wide, per tenant, or locked by administrator.
How is authorization enforced?
6 role tiers — Owner → SuperUser → Admin → Manager → Dispatch → Driver — with zone scoping enforced in platform middleware before any data is accessed, not in the UI layer.
What happens when a user is deactivated?
On deactivation, all active sessions and refresh tokens are invalidated in the same atomic transaction. There is no window between the two.
Is customer data segregated?
Every customer runs on a physically dedicated database. There is no shared multi-tenant table at any layer, so cross-customer exposure is not prevented by configuration — it has no path to occur.
How is that verified rather than asserted?
An automated probe writes a unique record to one customer's database daily and confirms it appears in no other. Results are recorded as timestamped evidence in the compliance ledger.
Is data encrypted?
Data in transit is TLS 1.2+ over HTTPS exclusively. Data at rest is encrypted by the underlying Cloudflare D1 platform. Customer-managed encryption keys are not currently offered.
What happens to our data if we leave?
On offboarding, your data is exported in standard CSV and deleted within 30 days. The process is logged and auditable.
Do you use customer data to train AI models?
No. Customer data is never used for model training. AI features are available only on the AI tier and are covered in the Data Processing Agreement.
How are integration endpoints authenticated?
Inbound webhooks are verified via HMAC-SHA256 signature before processing. Unsigned or tampered payloads are rejected.
How is API access authorized?
Short-lived, role-scoped JWTs. Middleware verifies the token and enforces role and zone permissions on every request before any data access occurs.
Is there a public API?
Yes — audit logs, asset history, and operational records are accessible and exportable via API using the same role-scoped authorization as the application.
Where does the platform run?
Cloudflare's global edge network. There is no on-premises component and no single-region dependency. Cloudflare's current SOC 2 Type II report is available from their Trust Hub.
Where is data stored geographically?
Data resides in the Cloudflare network. Region-pinned data residency is not currently offered; contact us if your requirements include EU or other regional residency.
Is infrastructure security your responsibility or your provider's?
Physical datacenter security, hypervisor isolation, and network infrastructure are Cloudflare's responsibility as our subservice organization, carved out of our SOC 2 scope. Application-layer and data-layer controls are ours.
What is logged?
Every authentication event, administrative action, permission change, and data modification, with actor identity, zone assignment, and timestamp.
Are logs tamper-resistant?
Audit records are append-only. Compliance evidence is additionally hash-chained, so any alteration breaks the chain and is detectable at the record where it occurred.
Can we get our logs?
Yes — CSV export by date range, up to 100,000 records per export, available to administrators without a support request.
How are vulnerabilities identified?
Dependency vulnerabilities are ingested automatically from GitHub Dependabot and reviewed weekly as a recorded compliance event.
What are your remediation timelines?
Critical within 7 days, High within 30, Medium within 90.
Do you perform penetration testing?
A third-party penetration test has not yet been performed. This is planned and we will share scope and results when available.
How are production changes controlled?
All changes flow through version control with required CI gates and a documented self-review checklist. Every merge to the production branch is captured as a timestamped compliance event via automated webhook.
Is there separation of duties in your deployment process?
TowerVue's engineering team is currently one person, so independent peer review is not available. This is documented as a known limitation with compensating controls: mandatory CI gates, a formal self-review checklist, and explicit flagging of self-merged changes for audit.
Are backups taken and tested?
Point-in-time recovery is maintained through the database platform, with recovery bookmarks captured weekly as evidence. Quarterly restore drills to verify recovery are scheduled for this audit window.
What are your recovery time and recovery point objectives?
RPO: Cloudflare D1's continuous point-in-time recovery captures every committed transaction — recovery to within seconds of any event in the last 30 days. RTO: 24 hours from declaration of a recovery event.
What is your uptime commitment?
99.5% monthly uptime under the Service Level Agreement, with service credits as the remedy. The AI assistant is carved out of the uptime commitment.
How are incidents handled?
Security incidents are tracked through a structured incident register with a documented response plan naming an incident commander and external escalation contacts.
Will you notify us?
Affected customers are notified within 72 hours of discovery.
Do you test the response plan?
An annual tabletop exercise is scheduled for the current audit window.
Who are your subprocessors?
Last updated: August 28, 2026.
Cloudflare, Inc. — edge infrastructure; all customer data at rest and in transit.
Resend — transactional email; user invitations and MFA delivery only.
Anthropic, PBC — AI inference; AI tier customers only.
We provide at least 30 days' notice before engaging a new sub-processor, per the Data Processing Agreement.
How are vendors assessed?
Third-party providers are reviewed quarterly for security posture, with each review recorded as a compliance event.
Do you notify us of subprocessor changes?
Yes, per the terms of the Data Processing Agreement.
Do you screen personnel?
Background screening is performed for personnel with production access, consistent with a documented HR security policy scaled to current team size.
Is security training conducted?
Annual security awareness training is included in the control set for this audit window.
Is our data portable?
Yes. Operational records, asset history, and audit logs export to standard CSV via API at any time. No proprietary formats.
Is there vendor lock-in?
No. Your data is accessible in open formats throughout, without a support request or an exit fee.
Known limitations
A page with no gaps implies gaps were hidden. Every item below would surface in diligence.
- —
SOC 2 Type II report not yet issued. The audit window opened June 22, 2026. Evidence collection is continuous and the package is available for review in the interim.
- —
Native SAML is not implemented. OIDC is supported directly. SAML-only environments are not currently supported.
- —
Single-engineer team. Independent peer review of code changes is not available. Compensating controls are documented in the Change Control section above.
- —
No customer-managed encryption keys. Encryption at rest is managed by the infrastructure provider.
- —
No regional data residency guarantee. Contact us if EU or other regional residency is a requirement.
Security questions or report requests
We respond to security inquiries within one business day.