Identity & access
- Email + password authentication, social sign-in, and enterprise SSO (SAML) for eligible plans.
- Role-based access control with least-privilege defaults. Roles are stored in a dedicated, server-validated table — never in client storage.
- Row-level security on every customer-facing data table.
- Optional leaked-password protection via the Have I Been Pwned database.
Encryption
- TLS 1.2+ in transit on all endpoints and email transports.
- AES-256 at rest for the primary datastore, including backups.
- Secrets stored in an isolated server vault — never embedded in client bundles.
Application security
- SDLC includes peer review, static analysis, and dependency scanning on every change.
- Automated security scans run continuously against the production codebase.
- Input validation, output encoding and CSP defaults aligned with OWASP ASVS L2.
- All public webhook endpoints require signature verification.
Infrastructure
- Hosted on enterprise edge infrastructure with global anycast and DDoS protection.
- Server functions run in isolated serverless workers with no persistent shell access.
- Automated backups with point-in-time recovery; disaster-recovery objectives RTO < 4h, RPO < 1h.
Monitoring & response
- Centralized audit logging of authentication, role changes, and admin actions.
- 24×7 alerting on anomalous behavior; on-call rotation with documented runbooks.
- Incident classification and notification within 72 hours where legally required.
Vendor & people security
- Vendor risk assessments before onboarding; annual reviews thereafter.
- Background checks, confidentiality agreements, and mandatory security training for staff.
- Hardware-key MFA enforced for engineering and admin roles.
Responsible disclosure
We welcome security research. Report suspected vulnerabilities to security@accredisense.ai. Please give us reasonable time to remediate before public disclosure. We do not pursue legal action against researchers acting in good faith.
Questions or requests?
Contact our team at privacy@accredisense.ai (privacy & data), security@accredisense.ai (security disclosures), or legal@accredisense.ai (legal & compliance).
This page is maintained by AccrediSense to answer common questions about Accredi Game. It is informational and does not constitute a certification, audit attestation, or legal advice.
