Security
Last updated: January 2025
Encryption
All media is encrypted in transit using DTLS-SRTP. Signaling is encrypted using TLS 1.3. Data at rest is encrypted using AES-256. Optional End-to-End Encryption (E2EE) is available for maximum privacy.
Compliance & Certifications
- SOC 2 Type II certified
- HIPAA compliant
- GDPR compliant
- PCI DSS compliant (billing systems)
- ISO 27001 certified (in progress)
Access Control
Production systems use role-based access control (RBAC) with least-privilege principles. All access is logged and audited. Multi-factor authentication is required for all internal systems.
Data Residency
Data is stored in your selected region (US, EU, or APAC). Enterprise customers can request specific data residency requirements. We do not cross-region replicate personal data.
Vulnerability Management
We run continuous vulnerability scanning and annual penetration tests. Security researchers can report vulnerabilities to security@gravixcloud.com. We maintain a responsible disclosure program.
Incident Response
We maintain a 24/7 incident response team. Security incidents are classified by severity and communicated to affected customers within 24 hours of confirmation.
Contact
For security questions or to report a vulnerability, contact security@gravixcloud.com. For urgent security matters, call +1 (415) 555-0199.
Ready to build on Gravix Cloud?
Start with 2,000 free minutes. Ship your first call in under an hour.