Skip to content

Security

Security at every layer, not bolted on

Your data is protected from the network edge to the disk. Encryption in transit and at rest, DDoS mitigation across the whole network, strict access controls and round-the-clock monitoring, on every account.

Security features

Built into the platform from day one

Security is a foundational principle of the infrastructure, not an afterthought or a premium tier.
  • Encryption in transit

    Everything to and from our services is encrypted with TLS 1.3. HTTPS is enforced on every endpoint.
  • Encryption at rest

    Customer data is stored with AES-256 encryption, using keys that are rotated regularly.
  • DDoS protection

    Mitigation built into the global network absorbs and filters malicious traffic before it reaches your infrastructure.
  • Access controls

    Role-based access, multi-factor authentication and API key management give you granular permissions.
  • Team security

    Every Edge employee is background-checked and trained. Production access is tightly controlled and audited.
  • Incident response

    24/7 security monitoring and defined response procedures. Affected customers are notified promptly.

Encryption

Encrypted on the wire and on the disk

Connections use TLS 1.3, and plain HTTP is redirected to HTTPS on every endpoint. Stored data is encrypted with AES-256, and the keys that protect it are rotated on a regular schedule.
  • TLS 1.3 for all data in transit
  • HTTPS enforced everywhere
  • AES-256 at rest with regularly rotated keys

Access & accountability

The right people, with the right permissions

Give each teammate the role they need, from Owner to read-only Viewer. Protect every login with two-factor authentication, revoke sessions from any device, and keep a full activity log for your own audits.
  • Owner, Admin, Developer and Viewer roles
  • TOTP two-factor authentication and API key management
  • Activity log with timestamps, IP addresses and user context

Compliance

Where we stand, stated plainly

We're committed to meeting industry standards and regulatory requirements, and the programme keeps evolving as we grow. Here's exactly where each one is today.

  • Compliant

    GDPR

    EU General Data Protection Regulation

  • In progress

    ISO 27001

    Information security management

  • In progress

    SOC 2 Type II

    Security and availability controls

Regular audits

Independent third parties run regular security audits and penetration tests so we can find and fix vulnerabilities.

Continuous monitoring

Our security team watches continuously for threats, vulnerabilities and anomalous activity across the infrastructure.

Responsible disclosure

Found a vulnerability? Tell us first.

We welcome security researchers. Report issues to us privately so we can fix them before anything is disclosed publicly, and include detailed steps to reproduce.
  1. 01

    You find an issue

    Spotted a vulnerability in Edge? Keep the details private for now.

  2. 02

    Report it privately

    Email security@edge.network with detailed steps to reproduce.

  3. 03

    We investigate and fix

    Our security team reproduces the issue and addresses it.

  4. 04

    Then it goes public

    Public disclosure follows once the issue is fixed.

FAQ

Security questions, answered

Is Edge ISO 27001 or SOC 2 certified?
Not yet. ISO 27001 and SOC 2 Type II are both in progress. Edge is compliant with the EU General Data Protection Regulation (GDPR) today.
How is my data encrypted?
In transit with TLS 1.3, with HTTPS enforced on every endpoint. At rest with AES-256, using regularly rotated keys.
What happens if there's a security incident?
We monitor our infrastructure 24/7 and follow defined incident response procedures. If a security event affects you, we notify you promptly.
Do you support SSO or SAML?
Talk to our enterprise team about SSO/SAML, custom retention policies and other advanced security requirements. Every account can already use two-factor authentication and sign in with Google or GitHub.
How do I report a vulnerability?
Email security@edge.network privately with a description of the issue and detailed steps to reproduce it.

Questions about security?

If you have specific security questions or requirements, our team is happy to help.

Reporting a vulnerability? Email security@edge.network privately.