Security Statement
An overview of the controls protecting client systems and data.
Last updated: September 1, 2026
01Network & edge
All public traffic is proxied through Cloudflare with WAF rules, bot management, rate limiting, and DDoS mitigation. Origins accept traffic only over TLS.
02Data isolation
Every tenant-owned record carries an organization_id. Postgres row level security policies restrict reads and writes to members of that organization, enforced at the database layer.
03Encryption
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Backups are encrypted and access-controlled.
04Access control
Staff access to production follows least privilege, requires MFA, and is logged. BPO agents only access the client systems and records assigned to them.
05Responsible disclosure
Report suspected vulnerabilities to sagar@largis.co. We acknowledge reports within two business days.