← Back to home

Security at Solviq

Last updated: 29 Jul 2026

Certifications

  • ISO 27001:2022 (in progress, expected Q4 2026)
  • SOC 2 Type II (in progress)
  • DPDP Act 2023 compliant

Infrastructure

  • AWS Mumbai (ap-south-1) primary, Singapore backup
  • Multi-AZ, auto-scaling, WAF, DDoS protection (Cloudflare)
  • Encrypted EBS volumes, KMS-managed keys
  • VPC isolation, private subnets, NAT gateway

Application

  • OWASP Top 10 mitigation in code review
  • CSRF tokens on all forms
  • Prepared statements, no raw SQL
  • Row-level tenant isolation (tenant_id on every query)
  • 2FA via TOTP available for all users
  • Sessions stored encrypted in DB, rotated on login

Personnel

  • Background checks on all employees
  • Annual security training
  • Least-privilege access to production
  • Code reviews required for all changes

Reporting

Found a vulnerability? Email security@solviq.app. We respond within 24 hours. Bug bounty program launching Q3 2026.