Enterprise Security Policy
Last updated: August 15, 2026. Comprehensive overview of our multi-tenant security architecture and vulnerability disclosure program.
1. Infrastructure Security & Isolation
ManRiq is hosted on ISO 27001, SOC 2 Type II, and PCI-DSS compliant cloud infrastructure. Multi-tenancy is enforced at the database level with tenant scopes on every query, ensuring zero cross-tenant contamination.
2. Cryptography & Key Management
All database connections and application endpoints mandate TLS 1.3. Tenant secrets, SMTP passwords, and SMS API credentials are encrypted with AES-256 using envelope key management. Storage media files reside in private Cloudflare R2 object stores with time-limited signed URLs.
3. Vulnerability Disclosure & Bug Bounty
We welcome security researchers to test our public attack surfaces responsibly. Report potential vulnerabilities directly to security@manriq.com. We pledge to triage reports within 24 hours.