Trust & security

Security is the product. It has to be the practice too.

How Parachute handles your incident data responsibly.

Security practices

Our security practices

Incident response tooling processes some of the most sensitive data in your environment. We take that seriously.

TLS 1.3 for all data in transit

Every connection to Parachute APIs, webhooks, and the dashboard is encrypted with TLS 1.3. Older TLS versions and all SSL versions are rejected. Certificate pinning is available for enterprise integrations.

AES-256 encryption at rest

All evidence packages, runbook definitions, and incident metadata are encrypted at rest using AES-256-GCM. Encryption keys are managed per-workspace and rotated automatically on a 90-day cycle.

Configurable evidence retention

Evidence data is deleted after your configured retention window expires. No evidence artifact persists beyond the window. Deletion is permanent and logged to your audit trail.

No employee access to customer incident data

No Parachute employee can access your incident data without your explicit written consent. Access requests are logged, time-limited, and require dual approval from our security team.

Webhook signatures for all inbound events

Every inbound webhook is verified with an HMAC-SHA256 signature before processing. Replay attacks are prevented with a 5-minute timestamp tolerance window.

Least-privilege IAM credentials

Parachute's cloud integration uses the minimum IAM permissions required for each runbook action. Credentials are stored encrypted and scoped to your workspace only.

Compliance

Compliance roadmap

We list the certifications we have completed, not the ones we are pursuing. If the status below is not sufficient for your evaluation, reach out and we will share current controls documentation.

GDPR

Data processing addendum available on request. EU data residency option in roadmap.

Australian Privacy Act

Compliant for AU-hosted customers. Data processed and stored within Australia on request.

SOC 2 Type II

Audit planned. Not yet certified. We will publish the report publicly when complete.

ISO 27001

Roadmap item. Controls implementation in progress alongside SOC 2 preparation.

We do not claim certifications we have not completed. If a specific compliance requirement is blocking your evaluation, contact us and we can provide documentation on current controls.

Data handling

What we do and don't do with your data

We DO

  • Process incident data to execute your runbooks
  • Store evidence artifacts for your configured retention window
  • Log all actions taken during runbook execution
  • Provide export of all your data on request
  • Delete all data on account closure

We DO NOT

  • Use your incident data to train AI models
  • Share your data with third parties for any purpose
  • Retain evidence beyond the configured window
  • Access your data without your explicit consent
  • Sell or monetise any customer data

Questions about our security practices?

Our security team responds to disclosure reports and security questions within one business day.