audit rights dpa residency · Privacy Policy
Anana policy finding
“ We apply the following measures: Encryption in transit: TLS everywhere; HTTPS-only externally. Encryption at rest: AES-256 via AWS KMS for AWS RDS Postgres 17.4 (including pgvector) and AWS S3 (recordings, attachments, exports). Application-level AES-256-GCM for integration credentials. Multi-tenant isolation: row-level tenant filter enforced in the application data layer. Network protection: AWS WAF with managed rules and rate limiting (2000 requests per 5 minutes). Webhook integrity: HMAC verification on inbound webhooks where the provider supports it. Access controls: multi-factor authentication, role-based access control, least-privilege provisioning. Audit logging: artifact lifecycle events (create, version bump, send) are recorded. Transient stores: Redis is used for sessions and queues; data there is short-lived.”
- Document
- Privacy Policy
- Captured
- 2026-07-19
- Location
- § 9 (Security)
- Snapshot SHA-256
- 8df01c2abdd5082967f7746351a01744cb2eda2b5f803804a9b804efa9beb02e
Informational only, not legal advice. Terms change; verify the source and capture date.