EpicShifts logo
EpicShifts™

Security & Compliance

Your data security is our top priority. We implement industry-leading security measures to protect your business.

Our Security Measures

Data Encryption

All data encrypted at rest using AES-256 and in transit with TLS 1.3.

Multi-Factor Authentication

TOTP-based MFA support for enhanced account security and protection.

Access Controls

Role-based access control (RBAC) with granular permissions and email verification.

Infrastructure Security

Hosted on secure cloud infrastructure with automated backups and disaster recovery.

24/7 Monitoring

Continuous security monitoring with automated threat detection and incident response.

Compliance & Certifications

Designed to meet GDPR requirements with SOC 2 Type II certification in progress.

Multi-Tenant Isolation

Strict data isolation between organizations with no cross-tenant data sharing.

Regular Audits

Third-party security audits and annual penetration testing to ensure protection.

Your Security Command Center

Every user gets powerful security controls built right into their settings — manage passwords, enable two-factor authentication, monitor active sessions, and review login history all in one place.

Security Settings

Compliance & Certifications

GDPR Ready
SOC 2 Type II (In Progress)
Regular Security Audits
Annual Penetration Testing

Security FAQs

We use industry-standard AES-256 encryption for data at rest and TLS 1.3 for data in transit. All access is logged and monitored 24/7. We implement role-based access controls and require multi-factor authentication for sensitive operations.

Your data is stored on AWS, an enterprise-grade cloud provider, with automated backups and disaster recovery. AWS data centers are SOC 2 certified with physical security controls and redundant systems.

Only authorized personnel with legitimate business needs can access customer data. All access is logged and audited. We implement strict role-based access controls and employee background checks.

We are actively working toward SOC 2 Type II certification. Our security practices already align with SOC 2 requirements including access controls, encryption, monitoring, and incident response procedures.

Please email [email protected] immediately with details about the vulnerability. We take all security reports seriously and respond within 24-48 hours. We appreciate responsible disclosure and will keep you updated on our investigation.

Report a Security Issue

We take security seriously. If you discover a vulnerability, please report it responsibly. We respond to all security reports within 24-48 hours.

Report Security IssueLast updated: February 2026
We Value Your Privacy

We use cookies to improve your experience on our platform. Essential cookies are required for the site to function properly (authentication, security). Optional cookies help us understand how you use the site and improve our services. Learn more about cookies