Security FAQ

Common questions from security & procurement teams. See also Security & Trust and the DPA.

Where is data hosted?

On our cloud/VPS infrastructure. Anchors (hashes + timestamps) are additionally recorded on the public Base blockchain. The current sub-processor list is on the Security & Trust page.

Is data encrypted?

In transit: yes — all traffic uses HTTPS/TLS. Passwords are stored as bcrypt hashes and API keys as hashes. For file anchoring, files are hashed in the browser and never uploaded.

How is access controlled?

Authentication with Secure, HttpOnly cookies; optional TOTP two-factor; per-account/IP rate limiting. Organizations use role-based access (admin/member) with an audit log of administrative actions. Administrative access to systems is limited to authorized personnel.

Do you support SSO?

Yes — single sign-on via OpenID Connect (Google Workspace, Microsoft Entra, Okta, and other OIDC providers) is available for organizations on institutional plans, along with SCIM provisioning and automatic deprovisioning. Two-factor authentication (TOTP) is available to all accounts. SAML is on the roadmap.

How do you handle vulnerabilities & incidents?

We patch dependencies and apply security best practices (CSP, SSRF protections, input validation, output escaping). Report issues to contact@chainanchor.io; we’ll respond promptly. In the event of a personal-data breach we notify affected customers without undue delay (see the DPA).

Backups & recovery?

The database is backed up; the most critical records (the proofs themselves) are also independently anchored on the public blockchain and remain verifiable even if our systems were unavailable.

Data residency?

Hosting region is configurable for enterprise customers — contact us. Note the public blockchain is global by nature, but it contains only fingerprints and timestamps, no personal content.

Can we get our data out / delete it?

Yes — export all anchors from the account page at any time, and delete the account to remove personal data. On-chain hashes/timestamps are permanent and cannot be deleted (by anyone).

Do you have SOC 2 / ISO 27001?

Not currently — formal certification is on our roadmap. We’re happy to share our security practices and complete reasonable security questionnaires in the meantime.

Penetration testing?

We welcome responsible disclosure and can arrange independent testing for enterprise engagements. Contact us to discuss.

Uptime / SLA?

The standard Service is provided without a formal SLA; uptime commitments are available as part of enterprise agreements.

Questions?

Email contact@chainanchor.io — we’re glad to help procurement and security reviews.