Infrastructure Security
This marketing site (torgix.ai) and the Torgix product (app.torgix.ai, where customer data is processed and stored) run on separate infrastructure. The controls below describe the product infrastructure, where your equipment and account data lives.
| Control | Detail | Status |
|---|---|---|
| Cloud Provider | Microsoft Azure (SOC 2 Type II, ISO 27001, PCI DSS Level 1 certified at the platform level) | Active (Azure) |
| Data Center Region | US-based Azure regions (application: Central US; database: Central US) | Active (Azure) |
| Physical Security | Microsoft Azure-managed; biometric access controls, 24/7 on-site security, video surveillance across Microsoft's certified data centers | Active (Azure) |
| Network Firewall | Azure network security controls restricting inbound traffic to required application ports | Active (Azure) |
| DDoS Protection | Azure DDoS Protection (Basic tier), included by default for all Azure resources | Active (Azure) |
| Infrastructure Redundancy | Redundant networking and power within Microsoft Azure's data centers | Active (Azure) |
| Availability Commitment | 99.5% monthly uptime commitment; a formal SLA is available on enterprise agreements | Active (Torgix) |
| Elastic Scale | Managed Azure App Service and Azure SQL Database scale compute and storage on demand as an account grows, with no re-platforming or data migration | Active (Azure) |
| Automated Backups | Daily database snapshots retained for 30 days | Active (Torgix) |
| Backup Encryption | Backups encrypted at rest using AES-256 | Active (Torgix) |
| Disaster Recovery | RTO target < 4 hours; RPO target < 24 hours; annual DR test | Active (Torgix) |
Data Encryption
| Control | Detail | Status |
|---|---|---|
| Encryption at Rest | AES-256 encryption for all stored data, including Azure SQL Database (Transparent Data Encryption) and Azure Blob Storage | Active (Azure) |
| Encryption in Transit | TLS 1.2 minimum, TLS 1.3 preferred, for all client-server communication | Active (Torgix) |
| SSL / TLS Certificates | Let's Encrypt certificates with auto-renewal; A+ rating target on SSL Labs | Active (Torgix) |
| Key Management | Encryption keys managed by Microsoft Azure (Transparent Data Encryption, Storage Service Encryption); database access secured via Azure Managed Identity (passwordless), application secrets managed separately | Active (Azure) |
| Password Hashing | User passwords hashed using bcrypt with salt (minimum cost factor 12) | Active (Torgix) |
Access Controls
| Control | Detail | Status |
|---|---|---|
| Multi-Factor Authentication (MFA) | Authenticator-app (TOTP) two-factor with one-time backup codes; an administrator can require it organization-wide | Active (Torgix) |
| Single Sign-On (SSO) | SAML 2.0 and OpenID Connect sign-on through your identity provider (Okta, Microsoft Entra ID, Google Workspace, and other standards-compliant providers) | Active (Torgix) |
| SCIM Provisioning | Automated user provisioning and deprovisioning over SCIM 2.0, so directory changes flow into Torgix without manual steps | Active (Torgix) |
| IP Address Allowlisting | Restrict user sign-in to approved IP addresses and CIDR ranges; token-authenticated integrations (SSO, SCIM, API) are unaffected | Active (Torgix) |
| Role-Based Access Control (RBAC) | Granular roles (Admin, Manager, Technician, Viewer) enforced at API and UI layer | Active (Torgix) |
| Multi-Tenant Data Isolation | Each customer's data is logically isolated; cross-tenant queries are architecturally prevented | Active (Torgix) |
| Session Management | Signed, HTTP-only session cookies with a fixed maximum lifetime and SameSite protection against cross-site use | Active (Torgix) |
| API Key Management | Scoped API keys with per-key permissions, expiration, and revocation | Active (Torgix) |
Product & Application Security
| Control | Detail | Status |
|---|---|---|
| Input Validation | All API inputs validated and sanitized; parameterized queries to prevent SQL injection | Active (Torgix) |
| OWASP Top 10 Mitigation | Development practices and code review aligned to OWASP Top 10 risks | Active (Torgix) |
| Dependency Scanning | Automated scanning of third-party libraries for known CVEs (GitHub Dependabot) | Active (Torgix) |
| Secure SDLC | Security review integrated into sprint planning and pull request process | Active (Torgix) |
| Rate Limiting & Throttling | API rate limiting to prevent abuse; per-key and per-IP throttling, including on sign-in and password-reset endpoints | Active (Torgix) |
| Cross-Site Request Forgery (CSRF) Protection | Origin-verified protection enforced on every state-changing request, layered on SameSite session cookies | Active (Torgix) |
| Secure File Handling | Uploaded files are served with content-type enforcement (nosniff) and a safe content disposition, so an uploaded file cannot execute as script in the browser | Active (Torgix) |
Monitoring & Incident Response
| Control | Detail | Status |
|---|---|---|
| Infrastructure Monitoring | Uptime and performance monitoring with automated alerting on Microsoft Azure | Active (Azure) |
| Application Error Monitoring | Real-time error tracking and alerting for application exceptions | Active (Torgix) |
| Audit Logging | All user actions and API calls logged with timestamp, user ID, and IP; retained 90 days, exportable as CSV or JSON and pullable into a SIEM over the REST API | Active (Torgix) |
| Incident Response Plan | Documented IRP with defined severity levels, escalation paths, and communication templates | Active (Torgix) |
| Breach Notification | Affected customers notified within 72 hours of confirmed breach detection | Active (Torgix) |
Organizational Security
| Control | Detail | Status |
|---|---|---|
| Security Policies | Documented information security policies reviewed and approved annually | Active (Torgix) |
| Acceptable Use Policy | AUP covering company systems, data handling, and customer data access restrictions | Active (Torgix) |
Data Handling & Privacy
| Control | Detail | Status |
|---|---|---|
| Data Classification Policy | Four-tier classification: Public, Internal, Confidential, Restricted, with handling requirements per tier | Active (Torgix) |
| Customer Data Ownership | Customers retain full ownership of their data; Torgix uses it only for service delivery | Active (Torgix) |
| Data Retention | Customer data retained for the contract term plus 30 days post-termination, then securely purged | Active (Torgix) |
| Right to Deletion | Customers may request full data deletion; fulfilled within 30 days of verified request | Active (Torgix) |
| Data Portability | Customers can export all their data in standard formats (CSV, JSON) at any time | Active (Torgix) |
| Privacy Policy | Published privacy policy covering data collection, use, retention, rights, and third-party sharing | Active (Torgix) |
| Sub-Processor Disclosure | List of sub-processors maintained and disclosed to customers upon request | Active (Torgix) |
Compliance & Certifications
SOC 2 Type II Active (Azure)
Microsoft Azure is SOC 2 Type II audited, covering security, availability, and confidentiality trust service criteria.
ISO 27001 Active (Azure)
Microsoft Azure holds ISO/IEC 27001 certification for its information security management system.
PCI DSS Active (Azure)
Microsoft Azure is PCI DSS Level 1 compliant for payment card data environments.
GDPR Active (Azure)
Microsoft Azure is GDPR compliant, with data processing agreements and EU Standard Contractual Clauses available through Microsoft.
📩 Report a Security Issue
We take security reports seriously. If you discover a potential vulnerability in Torgix, please contact us at security@torgix.ai.
- Acknowledgement within 48 hours
- Status update within 5 business days
- We do not pursue legal action against good-faith researchers
📞 Security & Privacy Contacts
Security issues: security@torgix.ai
Privacy requests: privacy@torgix.ai
Infrastructure trust: Microsoft Azure Trust Center ↗
This document is reviewed quarterly or upon material change.
Last reviewed: July 2026 • Torgix, Inc. • Privacy Policy • Terms of Service