Skip to content

Security Statement

An overview of the controls protecting client systems and data.

Last updated: September 1, 2026

01Network & edge

All public traffic is proxied through Cloudflare with WAF rules, bot management, rate limiting, and DDoS mitigation. Origins accept traffic only over TLS.

02Data isolation

Every tenant-owned record carries an organization_id. Postgres row level security policies restrict reads and writes to members of that organization, enforced at the database layer.

03Encryption

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Backups are encrypted and access-controlled.

04Access control

Staff access to production follows least privilege, requires MFA, and is logged. BPO agents only access the client systems and records assigned to them.

05Responsible disclosure

Report suspected vulnerabilities to sagar@largis.co. We acknowledge reports within two business days.