Continuum API
Security at Continuum

Built secure
from the ground up

Your contact data is sensitive. We treat it that way — with encryption at every layer, strict access controls, and full audit trails for enterprise customers.

Download DPAContact security team

Encryption everywhere

All data in transit is encrypted with TLS 1.2+. Data at rest is encrypted with AES-256 across our database (Supabase/AWS RDS) and all persistent storage volumes.

API key security

API keys are hashed with SHA-256 before storage — we never store a key in plaintext. Keys are scoped by permission level and can be revoked instantly.

Infrastructure isolation

Application servers communicate with the database over private networks only. The database is never publicly accessible. Network egress is restricted to known endpoints.

Enterprise SSO & MFA

Authentication is handled by WorkOS (SOC 2 Type II certified). Enterprise customers can enforce SSO via Okta, Azure AD, or Google Workspace, with MFA required for all members.

Audit logs

Every sensitive action — member invitations, role changes, key creation, SSO configuration — is recorded in tamper-evident audit logs accessible to org admins.

Breach notification

We commit to notifying affected customers within 72 hours of discovering a confirmed data breach, in line with GDPR Article 33 and our DPA obligations.

Compliance
GDPRCompliant
SOC 2In progress
CCPACompliant
DPAAvailable
Security ExhibitSubprocessorsPrivacy Policy

Common questions

Where is my data stored?

All data is stored in the United States on AWS infrastructure via Supabase (database) and Railway (application servers). We do not currently offer regional data residency.

Do you have a SOC 2 report?

We are actively working toward SOC 2 Type I certification. In the meantime, our Security Exhibit and DPA cover the same controls enterprise procurement teams review. Email security@continuumapi.com for the full exhibit.

Can I get a DPA signed?

Yes. Our standard DPA is available at continuumapi.com/legal/dpa. It is based on Bonterms Cloud Terms v1 and is accepted by most enterprise legal teams without redlines. Contact us to countersign.

Do you do penetration testing?

Yes, at least annually. Test reports are available to enterprise customers under NDA. Email security@continuumapi.com.

How do I report a vulnerability?

Email security@continuumapi.com with details. We commit to acknowledging reports within 24 hours and providing a resolution timeline within 72 hours. We follow coordinated disclosure.

Does Continuum access my data?

Continuum staff do not access customer data except to provide support at your explicit request, or as required by law. All access is logged.

Have a question not covered here? Email security@continuumapi.com — we respond within one business day.