Security

We view security as a fundamental governance requirement, not a feature set. Our architecture is a proactive, multi-layered defense that protects the confidentiality, integrity, and availability of your data.

Security at a glance

  • End-to-end encryption
  • Two-factor authentication
  • 24/7 threat detection
  • Formal incident response

Below is an overview of our security controls and practices, mapped directly to the core functions of the NIST Cybersecurity Framework (CSF 2.0).

Govern: a security-first culture

Our governance strategy prioritizes transparency and rigorous adherence to industry standards:

  • Transparency — full visibility into our security practices to foster trust with stakeholders.
  • Compliance — continuous alignment with best practices to manage enterprise risk.
  • High standards — industry-leading infrastructure and tools that maintain a hardened security posture.

Identify: know the environment, find risks early

We employ automated tools to maintain a comprehensive understanding of our environment and identify potential risks before they can be exploited.

  • Vulnerability management — AWS Inspector performs automated, continuous security assessments, ensuring early identification of vulnerabilities and strict adherence to infrastructure best practices.
  • Asset inventory and observability — CloudWatch and Elastic APM give us deep visibility into our cloud resources and application performance, so deviations in asset health surface immediately.

Protect: identity, access, and data security

We implement a Zero Trust-inspired architecture so only authorized users can access specific resources, and data remains unreadable to unauthorized entities.

Identity management and access control

  • Role-based access control — the principle of least privilege is enforced through roles, groups, and policies, so people access only what their workflows require.
  • Multi-factor authentication — two-factor authentication is enforced for administrative access, adding a critical layer of defense against credential compromise and phishing.
  • Network segmentation — sensitive dashboards, internal services, and endpoints are restricted to VPN-connected users, complementing identity controls with network perimeter security.

Data security

  • Data at rest — all data stored on our servers is encrypted.
  • Data in transit — all data moving across networks is encrypted via secure protocols (TLS/SSL).

Detect: continuous monitoring

  • Threat detection — Amazon GuardDuty continuously monitors workloads and accounts, providing intelligent detection of malicious activity, unauthorized behavior, and compromised instances.
  • Centralized logging and analysis — a dedicated logging stack built on Grafana and Loki aggregates logs in one place, letting our teams correlate events and detect operational anomalies swiftly.

Respond and recover: resilience by plan

  • Incident response plan — a formal framework to quickly detect, categorize, and mitigate security incidents.
  • Mitigation and recovery — protocols that contain incidents and restore services to full functionality, protecting both user data and platform integrity.

Responsible disclosure

Found something? We want to know. Report suspected vulnerabilities to our team and we will investigate quickly and keep you informed.

iECHO system status

Track real-time platform availability and incident updates on our public status page at status.iecho.org.