Last updated:
All network requests to Hello24x7 API endpoints are encrypted in transit using TLS 1.3. Data at rest is encrypted using AES-256 with key rotation on a 90-day schedule.
We enforce role-based access controls (RBAC), least-privilege principles, and require multi-factor authentication (MFA) for all administrative console operations.
We run daily automated security scans using industry-standard SAST/DAST tooling and hold annual SOC2 Type II audits. Reports are available to enterprise customers under NDA.
We operate an active bug bounty program. To report a security vulnerability, contact security@hello24x7.com with a detailed description. We commit to a 48-hour initial response.
Questions about our legal policies? legal@hello24x7.com