Security at Seayora
Seayora protects data and payments with encryption in transit, hardened and access-restricted infrastructure, secure development and review practices, least-privilege internal access, and continuous monitoring and audit logging.
Encryption in transit
Traffic to and from Seayora is protected using industry-standard TLS encryption, and sensitive fields are protected in storage. We continually work to align our encryption practices with current industry standards.
Hardened infrastructure
Our application and database run on hardened, access-restricted infrastructure. Databases are not exposed to the public internet and are reachable only by our application layer.
Secure development & review
We follow secure-development practices, review changes before release, and maintain audit and error logging to detect and investigate issues.
Least-privilege access
Internally, we apply the principle of least privilege. Access to production systems and sensitive data is limited to authorized personnel and protected by authentication controls.
Monitoring & logging
We maintain security and audit logging and monitor for anomalous activity so we can detect, investigate, and respond to potential security events.
Authentication
We enforce password complexity requirements, store passwords using one-way hashing, support multi-factor authentication (MFA), and offer single sign-on (SSO) with supported providers.
Data privacy & FCRA-regulated data
Screening data is regulated under the Fair Credit Reporting Act. Applicants enter sensitive identifiers such as their SSN directly in an encrypted portal, and screening results are handled in line with FCRA requirements including adverse-action support.