Your data, protected by design.
Security isn't a feature we added — it's the foundation we built on. From encryption to access controls to incident response, every layer of Ion is designed to keep your data safe.
Encryption
AES-256 at rest, TLS 1.3 in transit. Customer-managed encryption keys available on Enterprise.
Access control
SSO/SAML, SCIM provisioning, RBAC. Engineers don't have default access to customer data.
Audit logging
Every action — user, API, and admin — is logged and retained for 13 months. Exportable via API.
Infrastructure
Hosted on AWS in US, EU, and APAC regions. Private VPC deployment available for Enterprise.
Compliance
SOC 2 Type II, GDPR, CCPA. HIPAA available with BAA. Penetration tested quarterly by independent firms.
Incident response
24/7 monitoring, sub-15-minute detection, public incident reports within 72 hours of resolution.
Compliance status
| Standard | Status | Date |
|---|---|---|
| SOC 2 Type II | Current | Renewed March 2026 |
| GDPR | Compliant | Ongoing |
| CCPA | Compliant | Ongoing |
| ISO 27001 | In progress | Expected Q4 2026 |
| HIPAA | Available with BAA | On request |
Need our SOC 2 report or a custom security review? Contact us — we respond within one business day.
Have a security question?
Email us at security@ion.app or reach out via our contact form.
Contact our security team