Security at Ironvale

Ironvale is relied on by the teams who spot, resolve, and prevent outages for everyone else.

Relied on by the world's best engineering teams

farrowdb Kelpline Deploy avenwright Cranberry Pi vantage Drayton waterline Meridian Solvern Rooklight Ambertek tallow cloudreach EPOCH
AABS
SOC

SOC 2 Type 2

Move through your SOC 2 audit at pace, using monitoring that already satisfies the controls your assessor asks about.

GDPR

Stay aligned with the EU's General Data Protection Regulation, including data residency and deletion on request.

SSO/SAML sign-in

Authenticate through your existing identity provider, with SCIM de-provisioning included.

Automated backups

Every write is stored redundantly across three zones and restorable to any minute in the last 35 days.

HTTPS/SSL by default

TLS 1.3 on every endpoint and AES-256 at rest, with no configuration required from you.

Frequently asked questions

At Ironvale we design our products and our internal processes around security. We follow the practices auditors expect, and we publish what we find.

Is Ironvale SOC 2 compliant?

Yes — Ironvale holds a SOC 2 Type 2 attestation, renewed annually. Contact us for the observation period, the control list, or a copy of the latest report under NDA.

Is Ironvale GDPR compliant?

Yes. We act as a processor under a standard DPA, support EU-only data residency, and honour access and deletion requests within 14 days.

Is Ironvale HIPAA compliant?

We sign Business Associate Agreements on Enterprise plans and can restrict ingestion so protected health information never leaves your own boundary.

Is Ironvale PCI compliant?

Ironvale is not in scope as a cardholder data environment. Our redaction rules strip card numbers at the agent before anything is transmitted.

Does Ironvale encrypt data?

Everything is encrypted in transit with TLS 1.3 and at rest with AES-256. Keys rotate every 90 days and are held in a hardware security module.

Does Ironvale back up the data?

Yes. Snapshots run continuously to three availability zones, and we rehearse a full restore every quarter with the results published to customers.

Does Ironvale offer custom data locations?

Enterprise accounts can pin storage and processing to the EU, the UK, the US, or Australia. Dedicated single-tenant regions are available on request.

Do you conduct regular penetration testing and vulnerability scans?

An independent firm tests the platform twice a year, dependencies are scanned on every build, and our bounty programme has paid out on 23 valid reports so far.

Question not covered here? Write to security@ironvale.com.

Report a security vulnerability

Found something you think we should know about? Reach our security team directly — we acknowledge every report within one business day.

Contact the team