Security
How we protect your data
Security Commitment
iMOGL is committed to protecting the confidentiality, integrity, and availability of our platform and customer data. Security is embedded in every layer of our engineering and operations.
Compliance & Certifications
SOC 2 Type II (in progress — audit completion Q2 2025). GDPR compliant. CCPA compliant. We follow NIST Cybersecurity Framework best practices and undergo annual penetration testing by an independent third party.
Encryption
All data is encrypted at rest using AES-256. All data in transit uses TLS 1.3 with perfect forward secrecy. Database backups are encrypted with separate KMS-managed keys. Candidate credentials (CDL numbers, SSN for background checks) are field-level encrypted with customer-specific keys.
Access Control
We enforce role-based access control (RBAC) with least-privilege principles. Production access requires SSO + hardware MFA. All access is logged and reviewed quarterly. Background checks are required for all employees with production access.
Infrastructure
We host on AWS with multi-AZ redundancy. Databases are backed up every 6 hours with 30-day retention. We use VPC isolation, security groups, and WAF protection. DDoS mitigation is provided by CloudFront and AWS Shield.
Application Security
All code is reviewed by at least two engineers. We use SAST (Snyk), DAST (OWASP ZAP), and dependency scanning in CI/CD. Secrets are managed via AWS Secrets Manager. We run a private bug bounty program.
Incident Response
Our incident response team is available 24/7. We follow a documented runbook for detection, containment, eradication, and recovery. Customers are notified of security incidents within 72 hours per GDPR Article 34. Status page: status.imogl.com.
Data Residency
All customer data is stored in Canadian regions (ca-central-1). Cross-border storage is available upon request for Enterprise customers.
Vendor Security
All third-party vendors undergo security review before onboarding. We require SOC 2 or equivalent certifications, data processing agreements, and annual reassessment. Vendors include AWS, Stripe, Twilio, and Checkr (background checks).
Responsible Disclosure
If you discover a security vulnerability, please email security@imogl.com with details. We respond within 48 hours and provide acknowledgement, timeline, and credit (if desired). Please do not publicly disclose until we've had time to remediate.
