Skip to content
Security

Your data, protected by design.

Security isn't a feature we added — it's the foundation we built on. From encryption to access controls to incident response, every layer of Ion is designed to keep your data safe.

SOC 2 Type IIGDPRCCPAHIPAA-ready

Encryption

AES-256 at rest, TLS 1.3 in transit. Customer-managed encryption keys available on Enterprise.

Access control

SSO/SAML, SCIM provisioning, RBAC. Engineers don't have default access to customer data.

Audit logging

Every action — user, API, and admin — is logged and retained for 13 months. Exportable via API.

Infrastructure

Hosted on AWS in US, EU, and APAC regions. Private VPC deployment available for Enterprise.

Compliance

SOC 2 Type II, GDPR, CCPA. HIPAA available with BAA. Penetration tested quarterly by independent firms.

Incident response

24/7 monitoring, sub-15-minute detection, public incident reports within 72 hours of resolution.

Certifications

Compliance status

StandardStatusDate
SOC 2 Type IICurrentRenewed March 2026
GDPRCompliantOngoing
CCPACompliantOngoing
ISO 27001In progressExpected Q4 2026
HIPAAAvailable with BAAOn request

Need our SOC 2 report or a custom security review? Contact us — we respond within one business day.

Have a security question?

Email us at security@ion.app or reach out via our contact form.

Contact our security team