Security · Updated August 31, 2026
Security Policy.
Security is our foundation. Here are our measures, data protection practices, and how to report a vulnerability.
Measures
How we protect data.
Data protection
- End-to-end encryption for all data in transit and at rest
- Multi-factor authentication for all systems
- Regular security assessments and penetration testing
- Automated vulnerability scanning and patch management
- Data classification and access controls
Infrastructure security
- Secure cloud infrastructure with geographic redundancy
- 24/7 security monitoring and alerting
- Network segmentation and firewall protection
- Reverse-proxy rate limits on public APIs
- Regular backup and disaster recovery testing
Access control
- Role-based access control (RBAC)
- Principle of least privilege enforcement
- Regular access reviews and audits
- Secure authentication and authorization mechanisms
- Session management and timeout controls
Incident response
- 24/7 Security Operations Center monitoring
- Comprehensive incident response plan
- Automated threat detection and response
- Regular incident response drills and testing
- Timely notification of security incidents
Program
Management and training.
Security management
immunisense maintains a comprehensive security management program that includes regular risk assessments, security planning, and continuous monitoring of our security posture. Our dedicated security team ensures all systems and processes meet or exceed industry standards.
Information security
- Encryption — end-to-end for all data in transit and at rest
- Access control — strict role-based access and multi-factor authentication
- Network — TLS 1.2/1.3 only, HSTS preload, nginx rate limits on public APIs
- Monitoring — 24/7 continuous security monitoring and automated alerting
Employee training
All employees undergo comprehensive security training, including data protection, threat awareness, and incident response procedures. Regular security awareness programs keep our team current with the latest threats and best practices.
Vulnerability disclosure
Report a vulnerability to security@immunisense.com. Include steps to reproduce, affected URLs, and impact. Do not exploit beyond what is needed to demonstrate the issue, and do not disclose publicly until we have confirmed a fix. We aim to acknowledge reports within 48 hours.
Machine-readable contact file: /.well-known/security.txt
