TorqueX.ai torqueX.ai
// TRUST CENTRE LIVE STATUS · OPERATIONAL

Security and residency, on the record.

Our posture, certifications, infrastructure, and incident response. Updated when reality changes — not on a quarterly cadence.

// COMPLIANCE STATUS
SOC 2 Type II
TARGET Q4 2026
ISO 27001
TARGET 2027
GDPR
ALIGNED BY DESIGN
Honest targets only. What we don't have yet says so. Lying here costs enterprise deals.
// HOSTING & RESIDENCY

Primary compute and your database are hosted in the United States. Static assets and edge delivery run on Cloudflare's global network. Per-region data residency (EU / India pinning) is on the Enterprise roadmap — not a live capability yet; talk to us if you need it.

Layer Provider Region
Application compute Fly.io US (Ashburn, VA)
Database (Postgres) Neon US
Connected messaging accounts Unipile EU (France)
Object storage / CDN / edge Cloudflare (R2 + Workers) Global edge
Honest targets only — we don't claim residency regions we don't yet enforce.
// ENCRYPTION
IN TRANSIT
TLS 1.2+ · HSTS · OCSP stapling
AT REST
AES-256 · provider-managed keys (Neon · Cloudflare R2)
TENANT ISOLATION
Row-level, tenant-scoped on every query
// ACCESS CONTROLS
  • Role-based access; least-privilege defaults
  • MFA required for all TorqueX staff
  • Hardware-key SSH for production access
  • Audit log of all production access (immutable; 7-year retention for Enterprise)
// CONNECTED ACCOUNTS

We never store your account passwords. When you connect LinkedIn, WhatsApp, Instagram or email, you authenticate on that provider's own screen. We hold an opaque session reference — no password, no cookie, no session token — and you can revoke it from your own account settings at any time, without asking us.

Two consequences worth stating. Each account stays with the person it belongs to, so there is nothing to hand over when someone joins and nothing to reclaim when they leave. And there is nothing on our side to leak, because we never held it.

// AUTHENTICATION OPTIONS
Method Plans Notes
Password + MFA All TOTP / WebAuthn
Google OAuth All Sign-in only; no Gmail scope without explicit grant
SAML SSO Enterprise Auto-provisioning via SCIM 2.0
Session management All Configurable timeout, single-session enforce
// INFRASTRUCTURE
  • Compute on Fly.io (US); managed Postgres on Neon; object storage, CDN and edge on Cloudflare (R2 + Workers)
  • Tenant data isolated at the row level, scoped on every query
  • Dedicated database branch for Enterprise (no shared pool)
  • Container images pinned and rebuilt on CVE; dependency scanning on every push
// VULNERABILITY MANAGEMENT
  • Dependabot enabled across all repositories
  • Snyk weekly scans of production dependencies
  • Third-party penetration test annually (report under NDA)
  • Public bug bounty: enterprise@torquex.ai with PGP key fingerprint on request
// INCIDENT RESPONSE
SEV-1 NOTIFICATION < 1 hour
BREACH NOTIFICATION (GDPR) < 72 hours of awareness
POSTMORTEM PUBLISHED < 5 business days
STATUS PAGE status.torquex.ai
ON-CALL 24/7 rotation · PagerDuty
// BUSINESS CONTINUITY
BACKUPS
Every 6 hours · 30-day retention
RESTORE-TESTED
Quarterly
RPO
6 hours
RTO
4 hours
BACKUPS
Neon continuous backup + point-in-time restore
// SUBPROCESSORS

We use a minimal set of subprocessors. Customers are notified 30 days before any addition with a right to object.

Subprocessor Purpose Region
Fly.io Application compute hosting US
Neon Managed Postgres database US
Cloudflare Object storage (R2), CDN, edge / Workers Global edge
Unipile Messaging-account connectivity (LinkedIn, WhatsApp, Instagram) and the conversations the Service handles on them. SOC 2 Type II · GDPR · CASA Tier 2 EU (France)
Dodo Payments Payment processing (Merchant of Record) Global
SendGrid Transactional email US
Anthropic LLM inference for agent US (Zero data retention configured)
OpenAI LLM inference for agent US (Zero data retention configured)
OpenRouter LLM router US (proxies; no model training)
Google OAuth / Gmail connect (customer-initiated) Per Google terms
// Full DPA + sub-processor list →
// CONTACT + DISCLOSURE
Report a vulnerability.

enterprise@torquex.ai · PGP key fingerprint on request · 1-hour first response · 24/7.

// We don't sue researchers. Coordinated disclosure within 90 days.