Data security
Encrypted in transit and at rest, by default.
- AES-256 at rest (MongoDB Atlas)
- TLS 1.2+ in transit, HSTS preload
- bcrypt-hashed passwords with per-user salt
- AES-256-GCM-encrypted 2FA secrets
- Daily encrypted backups, point-in-time restore
Codaiq protects your data with industry-grade encryption, audited infrastructure, and clear contractual safeguards. Here's exactly how.
Encrypted in transit and at rest, by default.
Strong authentication, least-privilege by design.
Built on vetted, audited providers.
Privacy-first, GDPR-aligned, contracts on request.
Our compliance roadmap. We publish progress as audits complete.
SOC 2 Type II
External audit and report covering security, availability, and confidentiality.
ISO 27001
Information security management system certification.
HIPAA-ready
Optional BAA and controls for healthcare deployments.
Responsible disclosure, with safe-harbor protection.
Found a security issue? Please report it to security@codaiq.com. We acknowledge every valid report and work fixes promptly.
Acknowledge
Within 48 hours
Critical fix
Within 7 days
PGP key
On request
Safe harbor
Good-faith security research is welcome. If you act in good faith, comply with this policy, and do not access more data than necessary to demonstrate the issue, we will not pursue legal action and will work with you on disclosure.
Last updated · 18 May 2026
Search for a page or run an action.