Security Policy

How Entity Desk Protects Your Data

Entity Desk handles sensitive entity, shareholder, and compliance data on behalf of our customers. This page describes the technical and operational controls we use to protect it, and how to report a security concern.

Last reviewed: July 2026

Data Protection

Encryption at rest

Sensitive entity data — tax IDs, company numbers, registration numbers, and addresses — is encrypted with AES-256 before it is written to the database. Uploaded documents are encrypted with a unique, randomly generated key per customer.

Encryption in transit

All traffic to and from Entity Desk is encrypted with TLS. Our production infrastructure terminates connections through a managed reverse proxy with automatically renewed certificates.

Database-per-tenant isolation

Each customer is provisioned a dedicated, logically separate database rather than shared tables with a tenant identifier. This keeps one customer's records structurally separate from another's.

Bcrypt password hashing

User passwords are never stored in plain text. We hash credentials with bcrypt before they touch the database, and password reset requests never reveal whether an email address exists in our system.

Access & Platform Controls

Verified webhooks

Inbound webhooks from our payment processor and identity-verification provider are cryptographically verified using signature checks before any data is trusted or acted on.

Role-based access control

Staff and operator accounts operate under role- and module-based permissions, so access to sensitive functionality is scoped to what a given role actually needs.

Structured audit logging

Actions across the platform — logins, document access, entity changes, billing, and administrative activity — are recorded in a categorized audit trail with user, action, and timestamp.

KYC/AML tooling

For firms using our compliance workflows, Entity Desk integrates identity verification (KYC/KYB) and sanctions screening, and supports generating suspicious transaction reports as part of a firm's own compliance process.

Our Approach to Security

Security is an ongoing program, not a one-time achievement. As Entity Desk evolves, we continue to review, test, and harden the platform. A few things worth being upfront about:

  • Entity Desk uses server-side encryption to protect stored data. This is not end-to-end or zero-knowledge encryption — like most SaaS platforms, our infrastructure is capable of decrypting customer data to operate the product, and access is restricted through the role-based controls and audit logging described above.
  • Entity Desk provides tooling to help licensed firms meet their own KYC/AML and data protection obligations. Using our platform does not by itself make a firm compliant — regulatory compliance remains each customer's responsibility.
  • We do not currently publish a formal compliance certification (e.g. SOC 2 or ISO 27001). If your organization requires one as part of a vendor security review, contact us to discuss your requirements.

Reporting a Security Issue

If you believe you have found a security vulnerability in Entity Desk, we want to hear from it directly from you before it becomes a public issue. Please report it responsibly:

  • Email us with a description of the issue, the steps to reproduce it, and its potential impact.
  • Give us a reasonable amount of time to investigate and respond before disclosing the issue publicly or to any third party.
  • Avoid accessing, modifying, or deleting data that isn't yours, and avoid actions that could degrade service for other customers (e.g. denial-of-service testing, automated bulk scanning).
  • We will not pursue legal action against researchers who make a good-faith effort to follow this policy while investigating and reporting a vulnerability.

We aim to acknowledge new reports within 5 business days. We do not currently run a paid bug bounty program, but we credit researchers who report valid issues responsibly, if desired.

sales@entitydesk.com

Have security questions for a vendor review?

We're happy to walk your security or compliance team through our architecture and controls.

Back to overview