Security

Last updated: June 14, 2026

Security is foundational to how Edirae is built and operated. This page answers the questions teams most often ask before trusting us with their data — clearly, and without jargon.

If your question isn't covered here, email security@edirae.com and we'll get you an answer.

1. Where Your Data Is Stored

  • Edirae runs on DigitalOcean managed cloud infrastructure (compute, database, and object storage).
  • Encryption in transit: all traffic is served over HTTPS using TLS 1.2 or higher.
  • Encryption at rest: databases, backups, and stored files are encrypted at rest.
  • Production data is isolated from development and staging environments.

Specific data-region details are available on request for teams with residency requirements — contact security@edirae.com.

2. Who Has Access

  • Production access is restricted to the founder under a least-privilege model.
  • No third parties have access to your data beyond the subprocessors listed in section 7, each used strictly to operate the service.
  • Access to production systems requires authenticated, audited credentials.

3. Backups & Disaster Recovery

  • Automated, encrypted backups of production data are taken on a regular schedule.
  • Restore procedures are tested periodically to verify backups are usable.
  • Our infrastructure provider offers redundancy across its managed services to support recovery from failures.

4. Incident Response

If a security incident occurs, our approach is:

  • Detect — continuous monitoring and error tracking (via Sentry) surface anomalies early.
  • Triage — we assess scope, severity, and affected data.
  • Contain & remediate — we stop the issue and fix the root cause.
  • Notify — affected users are notified without undue delay, in line with applicable law.
  • Review — we conduct a post-incident review to prevent recurrence.

5. Data Deletion (GDPR-Aligned)

  • You can delete your account and associated data at any time.
  • You may also request deletion by emailing privacy@edirae.com.
  • Upon a verified request, personal data is removed within 30 days, except where retention is required by law.

For full details on what we collect and your rights, see our Privacy Policy.

6. Authentication & Account Security

  • Token-based authentication with short-lived access tokens and rotated refresh tokens.
  • Login history tracking with suspicious-login detection on new devices or locations.
  • Active-session management so you can review and revoke sessions.
  • Passwords are hashed; we never store them in plain text.

7. Subprocessors

We rely on a small set of trusted third-party providers to operate Edirae. Each receives only the data necessary for its function.

SubprocessorPurposeData Shared
DigitalOceanCloud hosting, compute, managed database, and object storageAll application and learning data (encrypted at rest)
ResendTransactional email deliveryName, email address, and message content
SentryError monitoring and reliability loggingError traces and limited technical metadata
PusherReal-time notifications and live updatesAccount identifiers and event payloads
StripePayment processingBilling details (handled by the processor; we do not store card numbers)
PolarPayment processing and merchant of recordBilling details (handled by the processor; we do not store card numbers)
PaystackPayment processingBilling details (handled by the processor; we do not store card numbers)
Anthropic, OpenAI, Google (Gemini), DeepSeek, MistralAI mentor, evaluation, and learning-content generationOnly the minimum context required per request

AI providers receive only the minimum data required per request, and we do not permit your content to be used to train third-party models.

8. Compliance & SOC 2 Status

We follow SOC 2-aligned security practices across access control, monitoring, and change management.

SOC 2: In progress — Type 1 audit scheduled for Q1 2027.

9. Reporting a Vulnerability

We welcome responsible disclosure. If you believe you've found a security issue, please email security@edirae.com with details and steps to reproduce. Please give us a reasonable opportunity to address the issue before public disclosure.

10. Contact

Our commitment

Security is never "done." We continuously improve our practices as Edirae grows, and we'll keep this page current as that work progresses.