Trust & security
Security is the product. It has to be the practice too.
How Parachute handles your incident data responsibly.
Security practices
Our security practices
Incident response tooling processes some of the most sensitive data in your environment. We take that seriously.
TLS 1.3 for all data in transit
Every connection to Parachute APIs, webhooks, and the dashboard is encrypted with TLS 1.3. Older TLS versions and all SSL versions are rejected. Certificate pinning is available for enterprise integrations.
AES-256 encryption at rest
All evidence packages, runbook definitions, and incident metadata are encrypted at rest using AES-256-GCM. Encryption keys are managed per-workspace and rotated automatically on a 90-day cycle.
Configurable evidence retention
Evidence data is deleted after your configured retention window expires. No evidence artifact persists beyond the window. Deletion is permanent and logged to your audit trail.
No employee access to customer incident data
No Parachute employee can access your incident data without your explicit written consent. Access requests are logged, time-limited, and require dual approval from our security team.
Webhook signatures for all inbound events
Every inbound webhook is verified with an HMAC-SHA256 signature before processing. Replay attacks are prevented with a 5-minute timestamp tolerance window.
Least-privilege IAM credentials
Parachute's cloud integration uses the minimum IAM permissions required for each runbook action. Credentials are stored encrypted and scoped to your workspace only.
Compliance
Compliance roadmap
We list the certifications we have completed, not the ones we are pursuing. If the status below is not sufficient for your evaluation, reach out and we will share current controls documentation.
GDPR
Data processing addendum available on request. EU data residency option in roadmap.
Australian Privacy Act
Compliant for AU-hosted customers. Data processed and stored within Australia on request.
SOC 2 Type II
Audit planned. Not yet certified. We will publish the report publicly when complete.
ISO 27001
Roadmap item. Controls implementation in progress alongside SOC 2 preparation.
We do not claim certifications we have not completed. If a specific compliance requirement is blocking your evaluation, contact us and we can provide documentation on current controls.
Data handling
What we do and don't do with your data
We DO
- Process incident data to execute your runbooks
- Store evidence artifacts for your configured retention window
- Log all actions taken during runbook execution
- Provide export of all your data on request
- Delete all data on account closure
We DO NOT
- Use your incident data to train AI models
- Share your data with third parties for any purpose
- Retain evidence beyond the configured window
- Access your data without your explicit consent
- Sell or monetise any customer data
Questions about our security practices?
Our security team responds to disclosure reports and security questions within one business day.