Serverless Architecture: The serverless nature of Enve deployment, managed by established cloud provider, offloads server management responsibilities, including security patching and maintenance, to the platform providers, enhancing the security posture of Enve.
Multi factor Authentication: Verification code is required for user sign up and password change to ensure no compromise of account access.
Encryption: Enve ensures data at rest and in transit is encrypted. Enve Object Store, for instance, uses AES-256 encryption for files stored at rest. Enve data has built-in protections, including role-based access controls to safeguard against unauthorized access.
DDoS Protection: Enve has automated DDoS mitigation for all deployments, blocking suspicious incoming traffic. Enve deploys Web Application Firewall (WAF) to protect against malicious actors to enhance application security.
Compliance: Enve is deployed on a cloud platform that has a SOC 2 Type 2 attestation for Security, Confidentiality, and Availability, among many other certifications such as ISO 27001, PCI DSS, DSA and NIS2. Built on the platform application framework, Enve inherits the application framework and runtime platform native security features with zero configuration.