Encryption in transit
TLS 1.2+ everywhere. Render enforces HTTPS.
Government contractors handle CUI, NDAs, and pricing data. Our security posture is enterprise-grade from day one — because federal contractors have to be.
TLS 1.2+ everywhere. Render enforces HTTPS.
Postgres + Redis encrypted on Render. Field-level Fernet encryption on PII (EIN, contact details, Stripe IDs).
Auth0 OIDC with JWKS-verified ID tokens. MFA required on Pro and Agency tiers.
Every login, billing event, data export, and agent action logged with structured JSON for SIEM ingestion.
Per-IP per-bucket sliding-window Redis limiter. Aggressive throttling on freemium endpoints.
Strict CSP with per-request nonce, HSTS preload, X-Frame DENY, Permissions-Policy zero.
Every webhook signature verified against STRIPE_WEBHOOK_SECRET. Unsigned events rejected.
security@agora-virtual.com · 90-day fix SLA · safe harbor for good-faith research
Send a detailed report to security@agora-virtual.com. We acknowledge within 1 business day, triage within 3, and credit you in the release notes once we ship the fix.