MASK

Security

Security at MASK.

Enterprise-grade security built into every layer of the platform, not bolted on as an afterthought.

Security practices

Layered defenses for
every threat vector.

Encryption in Transit

All data transmitted over TLS 1.2+. HTTPS enforced on all endpoints including redirect traffic.

Credential Security

Passwords hashed with bcrypt. API keys stored using irreversible SHA-256 hashing. httpOnly secure cookies.

Role-Based Access Control

10 granular roles enforced server-side on every API endpoint. Owner, Admin, Manager, Editor, Analyst, Billing, Developer, and Client roles.

Audit Logging

Significant actions recorded in an audit history with configurable retention controls. Authentication, permission changes, and admin operations.

Abuse Prevention

Automated heuristic URL risk scoring on links. Rate limiting per account and IP. Public abuse reporting pipeline.

Data Isolation

Multi-tenant architecture with strict workspace-level data isolation. Cross-workspace access is impossible by design.

Compliance

Compliance and data protection.

GDPR Aligned

Data minimisation, retention controls, export/deletion capabilities, and cross-border transfer transparency.

Single Sign-On

SAML single sign-on with your identity provider. In early access.

Privacy by Design

IP anonymisation options, configurable data retention, and minimal data collection principles.

Incident Response

Structured incident response procedures with breach notification commitments and forensic logging.

Security meets speed.

Need to review our security posture for procurement? We provide security questionnaire responses and can schedule a review call.

Contact Security Team