Security at MBGuards

We take security seriously. Learn how we protect your data and maintain the integrity of our platform.

Our Security Commitment

As a security company, we hold ourselves to the highest standards. We practice what we preach and continuously invest in protecting your data and our infrastructure. Security isn't just our product—it's our foundation.

Infrastructure Security

End-to-End Encryption

All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256 encryption.

SOC 2 Compliant Infrastructure

Our infrastructure is hosted on SOC 2 Type II certified cloud providers with enterprise-grade security controls.

Multi-Tenant Isolation

Row-level security ensures complete data isolation between customers. Your data is never accessible to other users.

DDoS Protection

Enterprise-grade DDoS mitigation protects our platform from volumetric and application-layer attacks.

Application Security

Authentication & Authorization

Secure authentication with email verification, password hashing using bcrypt, and session management. Role-based access control (RBAC) ensures users only access what they're authorized to.

Input Validation

All user inputs are validated and sanitized to prevent injection attacks. We use parameterized queries to protect against SQL injection and encode outputs to prevent XSS.

Rate Limiting

API endpoints are protected with rate limiting to prevent abuse and brute-force attacks. Suspicious activity triggers automatic temporary blocks.

SSRF Protection

Our scanning engine includes SSRF protections that prevent scanning of internal/private IP ranges, localhost, and other potentially malicious targets.

Audit Logging

All security-relevant actions are logged with timestamps, user identifiers, and IP addresses for forensic analysis and compliance requirements.

Safe Scanning Practices

Non-Intrusive Scanning

Our scans are passive and non-intrusive. We only analyze publicly accessible information and never attempt to exploit vulnerabilities or access protected resources.

Domain Verification Required

You must verify domain ownership via DNS before scanning. This prevents unauthorized scanning of third-party websites and ensures ethical use of our platform.

No Performance Impact

Scans are designed to have minimal impact on your website's performance. We use polite crawling practices and respect robots.txt directives.

Credential Security

If you provide FTP/SFTP credentials for auto-fix features, they are encrypted at rest and only decrypted momentarily during the remediation process.

Compliance & Certifications

SOC 2

SOC 2 Compliant

Our infrastructure meets SOC 2 Type II requirements for security, availability, and confidentiality.

GDPR

GDPR Compliant

We comply with GDPR requirements for data protection, including data minimization and right to deletion.

OWASP

OWASP Standards

Our security checks align with OWASP Top 10 guidelines and best practices for web application security.

PCI

PCI-DSS Ready

Our reports help you meet PCI-DSS requirements for maintaining secure web applications.

Responsible Disclosure

We value the security research community and encourage responsible disclosure of any vulnerabilities you may find in our platform.

If you discover a security issue, please email us at security@mbguards.com with details of the vulnerability. We commit to:

  • Acknowledge receipt within 24 hours
  • Provide regular updates on our investigation
  • Fix confirmed vulnerabilities promptly
  • Credit researchers who help improve our security (with permission)

Please do not publicly disclose issues until we've had a chance to address them.

Questions about our security?

Our team is happy to discuss our security practices in more detail.