Infrastructure Encryption Access Controls Application Security Monitoring Organizational Data Handling Compliance
🖥
Infrastructure Security

This marketing site (torgix.ai) and the Torgix product (app.torgix.ai, where customer data is processed and stored) run on separate infrastructure. The controls below describe the product infrastructure, where your equipment and account data lives.

ControlDetailStatus
Cloud ProviderMicrosoft Azure (SOC 2 Type II, ISO 27001, PCI DSS Level 1 certified at the platform level)Active (Azure)
Data Center RegionUS-based Azure regions (application: Central US; database: Central US)Active (Azure)
Physical SecurityMicrosoft Azure-managed; biometric access controls, 24/7 on-site security, video surveillance across Microsoft's certified data centersActive (Azure)
Network FirewallAzure network security controls restricting inbound traffic to required application portsActive (Azure)
DDoS ProtectionAzure DDoS Protection (Basic tier), included by default for all Azure resourcesActive (Azure)
Infrastructure RedundancyRedundant networking and power within Microsoft Azure's data centersActive (Azure)
Availability Commitment99.5% monthly uptime commitment; a formal SLA is available on enterprise agreementsActive (Torgix)
Elastic ScaleManaged Azure App Service and Azure SQL Database scale compute and storage on demand as an account grows, with no re-platforming or data migrationActive (Azure)
Automated BackupsDaily database snapshots retained for 30 daysActive (Torgix)
Backup EncryptionBackups encrypted at rest using AES-256Active (Torgix)
Disaster RecoveryRTO target < 4 hours; RPO target < 24 hours; annual DR testActive (Torgix)
🔐
Data Encryption
ControlDetailStatus
Encryption at RestAES-256 encryption for all stored data, including Azure SQL Database (Transparent Data Encryption) and Azure Blob StorageActive (Azure)
Encryption in TransitTLS 1.2 minimum, TLS 1.3 preferred, for all client-server communicationActive (Torgix)
SSL / TLS CertificatesLet's Encrypt certificates with auto-renewal; A+ rating target on SSL LabsActive (Torgix)
Key ManagementEncryption keys managed by Microsoft Azure (Transparent Data Encryption, Storage Service Encryption); database access secured via Azure Managed Identity (passwordless), application secrets managed separatelyActive (Azure)
Password HashingUser passwords hashed using bcrypt with salt (minimum cost factor 12)Active (Torgix)
🔑
Access Controls
ControlDetailStatus
Multi-Factor Authentication (MFA)Authenticator-app (TOTP) two-factor with one-time backup codes; an administrator can require it organization-wideActive (Torgix)
Single Sign-On (SSO)SAML 2.0 and OpenID Connect sign-on through your identity provider (Okta, Microsoft Entra ID, Google Workspace, and other standards-compliant providers)Active (Torgix)
SCIM ProvisioningAutomated user provisioning and deprovisioning over SCIM 2.0, so directory changes flow into Torgix without manual stepsActive (Torgix)
IP Address AllowlistingRestrict user sign-in to approved IP addresses and CIDR ranges; token-authenticated integrations (SSO, SCIM, API) are unaffectedActive (Torgix)
Role-Based Access Control (RBAC)Granular roles (Admin, Manager, Technician, Viewer) enforced at API and UI layerActive (Torgix)
Multi-Tenant Data IsolationEach customer's data is logically isolated; cross-tenant queries are architecturally preventedActive (Torgix)
Session ManagementSigned, HTTP-only session cookies with a fixed maximum lifetime and SameSite protection against cross-site useActive (Torgix)
API Key ManagementScoped API keys with per-key permissions, expiration, and revocationActive (Torgix)
🛡
Product & Application Security
ControlDetailStatus
Input ValidationAll API inputs validated and sanitized; parameterized queries to prevent SQL injectionActive (Torgix)
OWASP Top 10 MitigationDevelopment practices and code review aligned to OWASP Top 10 risksActive (Torgix)
Dependency ScanningAutomated scanning of third-party libraries for known CVEs (GitHub Dependabot)Active (Torgix)
Secure SDLCSecurity review integrated into sprint planning and pull request processActive (Torgix)
Rate Limiting & ThrottlingAPI rate limiting to prevent abuse; per-key and per-IP throttling, including on sign-in and password-reset endpointsActive (Torgix)
Cross-Site Request Forgery (CSRF) ProtectionOrigin-verified protection enforced on every state-changing request, layered on SameSite session cookiesActive (Torgix)
Secure File HandlingUploaded files are served with content-type enforcement (nosniff) and a safe content disposition, so an uploaded file cannot execute as script in the browserActive (Torgix)
🚨
Monitoring & Incident Response
ControlDetailStatus
Infrastructure MonitoringUptime and performance monitoring with automated alerting on Microsoft AzureActive (Azure)
Application Error MonitoringReal-time error tracking and alerting for application exceptionsActive (Torgix)
Audit LoggingAll user actions and API calls logged with timestamp, user ID, and IP; retained 90 days, exportable as CSV or JSON and pullable into a SIEM over the REST APIActive (Torgix)
Incident Response PlanDocumented IRP with defined severity levels, escalation paths, and communication templatesActive (Torgix)
Breach NotificationAffected customers notified within 72 hours of confirmed breach detectionActive (Torgix)
👥
Organizational Security
ControlDetailStatus
Security PoliciesDocumented information security policies reviewed and approved annuallyActive (Torgix)
Acceptable Use PolicyAUP covering company systems, data handling, and customer data access restrictionsActive (Torgix)
📂
Data Handling & Privacy
ControlDetailStatus
Data Classification PolicyFour-tier classification: Public, Internal, Confidential, Restricted, with handling requirements per tierActive (Torgix)
Customer Data OwnershipCustomers retain full ownership of their data; Torgix uses it only for service deliveryActive (Torgix)
Data RetentionCustomer data retained for the contract term plus 30 days post-termination, then securely purgedActive (Torgix)
Right to DeletionCustomers may request full data deletion; fulfilled within 30 days of verified requestActive (Torgix)
Data PortabilityCustomers can export all their data in standard formats (CSV, JSON) at any timeActive (Torgix)
Privacy PolicyPublished privacy policy covering data collection, use, retention, rights, and third-party sharingActive (Torgix)
Sub-Processor DisclosureList of sub-processors maintained and disclosed to customers upon requestActive (Torgix)
📋
Compliance & Certifications
SOC 2 Type II  Active (Azure)
Microsoft Azure is SOC 2 Type II audited, covering security, availability, and confidentiality trust service criteria.
ISO 27001  Active (Azure)
Microsoft Azure holds ISO/IEC 27001 certification for its information security management system.
PCI DSS  Active (Azure)
Microsoft Azure is PCI DSS Level 1 compliant for payment card data environments.
GDPR  Active (Azure)
Microsoft Azure is GDPR compliant, with data processing agreements and EU Standard Contractual Clauses available through Microsoft.

📩 Report a Security Issue

We take security reports seriously. If you discover a potential vulnerability in Torgix, please contact us at security@torgix.ai.

  • Acknowledgement within 48 hours
  • Status update within 5 business days
  • We do not pursue legal action against good-faith researchers

📞 Security & Privacy Contacts

Security issues: security@torgix.ai

Privacy requests: privacy@torgix.ai

Infrastructure trust: Microsoft Azure Trust Center ↗

This document is reviewed quarterly or upon material change.

Last reviewed: July 2026 • Torgix, Inc. • Privacy PolicyTerms of Service

Security you can hand to your IT team.

Start a free trial. Full platform, no credit card, cancel anytime.

Start Free Trial →
Start Free Trial →