Security

Your data security is our top priority.

networkos is built from the ground up with security best practices. We protect your network data with multiple layers of defense.

Security Features

Comprehensive protection at every layer of the application

K

Cryptographically Signed Sessions

Every user session is protected with industry-standard JWT tokens signed using HS256 cryptographic algorithms. Session tokens cannot be forged or tampered with.

S

CSRF Protection

All state-changing operations are protected against Cross-Site Request Forgery attacks using the double-submit cookie pattern with cryptographically secure tokens.

R

Rate Limiting

Intelligent rate limiting protects against brute force attacks and API abuse. Authentication endpoints have stricter limits to prevent credential stuffing.

H

Security Headers

Comprehensive HTTP security headers including Content-Security-Policy, HSTS, X-Frame-Options, and X-Content-Type-Options protect against common web vulnerabilities.

Q

SQL Injection Prevention

All database queries use parameterized statements through Prisma ORM, preventing SQL injection attacks. No user input ever directly touches raw SQL.

E

Data Encryption

Sensitive credentials like OAuth tokens are encrypted at rest using AES-256-GCM encryption. All data in transit is protected with TLS 1.3.

Compliance & Certifications

Meeting industry standards for data protection and privacy

·

SOC 2 Type II

Provider

Our cloud infrastructure provider maintains SOC 2 Type II. NetworkOS runs on their certified infrastructure and is not separately SOC 2 certified.

GDPR data rights

Supported

We support data-subject rights for EU residents, including access, deletion, and export.

CCPA data rights

Supported

We support privacy rights for California residents, including access and deletion.

CASA Tier 2

In progress

Cloud Application Security Assessment for our Google OAuth scopes, currently underway.

practices

Our Security Practices

Security is embedded in everything we do, from development to deployment.

  • Regular security audits and penetration testing
  • Automated vulnerability scanning in CI/CD pipeline
  • Principle of least privilege for all system access
  • Comprehensive audit logging for security events
  • Incident response plan with defined escalation procedures
  • Employee security awareness training
  • Secure development lifecycle practices
  • Third-party dependency vulnerability monitoring

Report a Vulnerability

Found a security issue? We appreciate responsible disclosure.

support@thenetworkos.com

Questions about our security?

Our team is happy to discuss our security practices and answer any questions.