Skip to content
At a glance 5 KEY POSTURE METRICS
AES-256 Encryption at rest
TLS 1.3 Encryption in transit
99.5% Uptime SLA
< 72hr Breach notification
US only Data residency
Infrastructure GCP · US REGIONS · 6 CERTIFICATIONS

Built on Google Cloud.

Enterprise-grade infrastructure with certifications trusted by the world's most regulated industries. All data stored and processed in US regions.

Hail Sentinel's own certification

Our SOC 2 Type II audit is on our roadmap for 2026–2027, once our customer mix justifies the audit cycle. Until then, our standing posture is documented in the Security Practices Overview and Questionnaire below, running on SOC 2-certified Google Cloud. The attestations listed below belong to Google Cloud Platform, not Hail Sentinel.

Stack layers
4 LAYERS
Application layer Firebase App Check, RBAC, API Scoping
Network layer TLS 1.3, CORS, CSP, HSTS
Data layer AES-256, Cryptographic Key Hashing, Signed Webhooks
Infrastructure layer Google Cloud Platform, Infrastructure as Code, Automated Scanning
GCP certifications
6 ACTIVE

All Hail Sentinel infrastructure inherits the following attestations via Google Cloud Platform:

SOC 2 Type II ISO 27001 ISO 27017 ISO 27018 PCI DSS CSA STAR

Primary region us-central1 · BigQuery US multi-region · Firestore nam5

Controls APP · NETWORK · DATA · INFRA

Your data, protected at every layer.

Encryption, access control, and auditability baked into every request — from the mobile client to the BigQuery row.

Encrypted everywhere

AES-256 at rest, TLS 1.3 in transit. API keys cryptographically hashed. Webhook payloads signed with replay protection.

Access controlled

Role-based permissions. Scope-based API keys. Native device attestation on iOS and Android. Rate limiting on all endpoints.

Continuously audited

Comprehensive audit logs across all services. Structured request logging. Real-time monitoring with automated alerts.

SSRF protection

Private IP blocking on outbound requests. Validated webhook URLs. HTTPS enforced on every integration.

Privacy by design

Geohash discretization. Firebase UID pseudonymization. No ad tracking. No data selling.

Infrastructure as code

All resources defined in Terraform. Automated TFSec scanning on every deploy. Pinned versions, signed artifacts.

Compliance 6 FRAMEWORKS

Frameworks we follow.

Meeting the standards your legal and security teams require.

CCPA / CPRA California privacy
State privacy laws CO, CT, TX, UT, VA
COPPA Children under 13
CAN-SPAM Email compliance
OWASP Top 10 Web app security
App Store Apple + Google policies
Data retention 7 CATEGORIES

How long we keep things.

Clear policies for how long we store each category of data and why.

Retention schedule
7 ROWS
Account data Active + 3 years Service delivery
Location data (real-time) Not stored Processed in-memory
API logs 90 days Debugging & analytics
Security audit logs 3 years Compliance
Transaction records 7 years Legal requirement
Analytics 26 months Product improvement
Support communications 3 years Service quality

Data deletion available on request under CCPA/CPRA and other U.S. state privacy laws. Contact privacy@hailsentinel.com.

Subprocessors 5 VETTED · ALL US

Who else touches your data.

We carefully vet every third party that processes your data and give 30 days advance notice before adding or replacing one.

Google Cloud Platform Infrastructure
US
Firebase Auth & database
US
RevenueCat Subscriptions
US
Twilio SMS alerts
US
SendGrid Email alerts
US
Documents OVERVIEW · QUESTIONNAIRE · V1.0
Security Practices Overview
VIEW · PRINT

Our infrastructure architecture, encryption standards, access controls, compliance framework, incident response, and vendor management. Share with your security team or attach to compliance questionnaires.

Security Questionnaire Response
SIG-LITE · PRINT

Our standing answers to common third-party security questionnaire items — company info, data security, vendor management, business continuity, and compliance posture. Full SIG-Lite or CAIQ on request via legal@hailsentinel.com.

Resources 8 LINKS · SECURITY TEAM
Contact security

Our team is ready to discuss your security requirements, provide documentation, or address compliance questionnaire items.

security@hailsentinel.com
Contact security team