Security
Last updated: 2026-06-04
Security is foundational to Armore. This page summarizes the controls we operate to protect your data and your workflows. Our SOC 2 Type II program is in progress; the live control map is available to authenticated workspace admins under Settings → Compliance.
1. Authentication & Access
- Email/password and OAuth sign-in, plus SAML 2.0 SSO (Okta, Azure AD, Google Workspace)
- IdP-enforced MFA via SSO; JIT provisioning for enterprise workspaces
- Role-based access control (admin / editor / viewer) with per-tenant workspace isolation
- Short-lived JWTs with server-side revocation (logout denylist)
2. Data Protection
- TLS 1.2+ enforced in transit; HSTS with a two-year max-age
- OAuth and integration tokens encrypted at rest with AES-256-GCM
- Every Prisma query is workspace-scoped so tenants never read each other's data
- Audit-log retention with automated purge on a defined schedule
3. Application Security
- Content Security Policy, X-Frame-Options, and CSRF protection on state-changing requests
- HMAC-SHA256 signatures on inbound and outbound webhooks
- Rate limiting on public endpoints, per-IP and per-user
- Dependency scanning (Dependabot) and ESLint security rules in CI
4. Monitoring & Incident Response
- Real-time error monitoring (Sentry) and health checks across DB, cache, and LLM providers
- Daily anomaly scans for unusual failure or queue-growth patterns
- Dead-letter queue with replay for failed workflow executions
- Automated database backups with point-in-time recovery
5. Change Management
All changes ship through pull requests with required CI gates (typecheck, lint, tests). Direct pushes to production branches are blocked, and deployments are rollback-capable.
6. Reporting a Vulnerability
If you believe you have found a security issue, please email security@armore.ai with details and reproduction steps. We acknowledge reports promptly and will keep you updated through resolution. Please do not publicly disclose an issue until we have had a chance to address it.
7. Contact
Cognileap Eduventures LLP
Email: security@armore.ai
Address: Bangalore, India
