Security
We store data about your vendors. Here is exactly how we protect it.
Your vendor roster represents your organization's supply chain. We understand that sharing it with a monitoring platform requires trust. This page explains the controls we have in place, the practices we follow, and the certifications we are working toward.
Technical Controls
How we protect data in the platform
Controls applied to all customer data stored and processed by Magnitude.
Encryption in Transit
All data transmitted between your browser, our API, and Magnitude backend infrastructure is encrypted using TLS 1.3. Older TLS versions and unencrypted connections are rejected at the load balancer. HSTS is enforced with a minimum 12-month max-age.
Encryption at Rest
Vendor roster data, alert records, and configuration data are encrypted at rest using AES-256. Encryption keys are tenant-isolated using AWS KMS, so a key exposure in one tenant cannot affect another.
Role-Based Access Control
Magnitude seats have three permission levels: Viewer, Analyst, and Admin. Viewer seats can see alerts and vendor status but cannot modify roster or configure integrations. All permission changes are logged with the acting user and timestamp.
Audit Logs
All access to vendor data, alert acknowledgments, configuration changes, and integration events are captured in immutable audit logs. Logs are retained for 12 months and can be exported to CSV or forwarded to your SIEM via webhook.
US-Region Data Residency
All customer data is stored and processed in AWS US-East-1 and US-West-2 regions. No customer data is transferred to or processed in non-US infrastructure. Contractual data residency addendums are available upon request for enterprise plans.
SSO and MFA Support
Enterprise plans support SAML 2.0 single sign-on with your identity provider. All plans support TOTP authenticator-app MFA. Password-only authentication without MFA is not permitted for Admin seats.
Data Practices
What data Magnitude collects and how it is used
Transparency about what enters our platform and how we handle it.
What you bring to Magnitude
Your vendor roster: vendor names, primary contact information if you choose to include it, vendor categories, and any internal tier or risk classification you assign. Magnitude uses this solely to match against intelligence signals. We do not sell, share, or aggregate roster data across customer accounts.
What Magnitude generates
Risk alert records: signal matches against your vendors, severity scores, evidence source references, and your team's acknowledgment history. These records are stored per-tenant and are exportable or deletable on request. Aggregate, anonymized signal patterns may be used to improve matching accuracy.
Subprocessor disclosure
We rely on AWS (compute and storage), Stripe (billing), and a US-based transactional email provider for infrastructure. Full subprocessor list is available in our Data Processing Addendum, which is part of the enterprise plan agreement and available on request for Monitor and Manage plans.
Data deletion and portability
You can export your complete vendor roster and alert history at any time from the Magnitude dashboard in CSV format. On account closure, your data is deleted from production systems within 30 days and from backup systems within 90 days. Deletion confirmation is provided in writing.
Questions about how we handle your data?
Our security team will walk you through our controls and documentation during the pre-access evaluation. No obligation.