Source
Security / trust page — Agorapulse
Checked for Agorapulse on 30 Sep 2026
- Page
- https://www.agorapulse.com/security/
- Checked
- 30 Sep 2026, 12:38 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:6e2ee0ad8d1dad98f9fe4d304dcc0dec37f7990467613832c2e6ec0eda543750
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Provider Report an error
“Our service is built on Amazon Web Services (AWS).”
-
Region Report an error
“Data Location Customer Data are hosted in AWS Ireland region.”
-
Own infrastructure Report an error
“We don’t host or run our own routers, load balancers, DNS servers, or physical servers.”
-
Encryption in transit Report an error
“All data sent to or from our infrastructure is encrypted in transit via industry best-practices using Transport Layer Security (TLS).”
-
Encryption at rest Report an error
“All our user data (including passwords and access tokens) is encrypted using battled-proofed encryption algorithms in the database.”
-
Uptime target Report an error
“Our goal is to avoid any downtime at all costs and provide 99.9% uptime.”
-
Status page Report an error
“You can follow in real time the current status of our services here: https://status.agorapulse.com/.”
-
Backups Report an error
“We back up all our critical assets and regularly attempt to restore the backup to guarantee a fast recovery in case of disaster. All our backups are encrypted.”
-
Internal development Report an error
“All Agorapulse apps and services are 100% developed internally by full-time employees without any outsourcing.”
-
Owasp Report an error
“We follow OWASP (Open Web Application Security Project) standard security controls for the application security.”
-
Rbac Report an error
“Agorapulse uses a role-based access control (RBAC) approach to determine user access privileges required.”
-
Auth methods Report an error
“Authentication on Agorapulse can be handled via Facebook Connect and/or email+password.”
-
Password storage Report an error
“When email+password login is enabled, passwords are stored one-way hashed with random salt.”
-
Audit trail Report an error
“We collect and store logs to provide an audit trail of our applications activity.”
-
Ids ips Report an error
“An Intrusion Detection and/or Prevention technologies (IDS/IPS) solution that monitors and blocks potential malicious packets”
-
Vpc Report an error
“A virtual private cloud (VPC), a bastion host, or VPN with network access control lists (ACLs) and no public IP addresses”
-
Ip filtering Report an error
“IP address filtering”
-
Production access Report an error
“Access into both development and production environments requires both SSH keys and 2FA. Only our Engineering Ops team has access to our production environment.”
-
Employee 2FA Report an error
“We enable mandatory 2FA for all employees on all strategic services where it is supported.”
-
Device management Report an error
“Employee devices are managed by through a device management program to ensure that our fleet runs with the latest security fixes and secure configuration (encrypted disk, firewall, etc).”
-
Security training Report an error
“All new hires are provided with security on-boarding training, which includes setup and training on using a password manager and detecting phishing or social engineering.”
-
Pentest Report an error
“Our application and production network are tested every year by an independent penetration testing firm.”
-
Bug bounty Report an error
“We do not run a bug bounty program and we do not offer monetary rewards.”
-
Vulnerability disclosure Report an error
“We will not pursue legal action against researchers who follow these guidelines and report in good faith.”
-
Vendor certifications Report an error
“They provide strong security measures to protect our infrastructure and are compliant with most certifications (Cloud Security Alliance Star Level 2, ISO 9001, 27001, 27017, 27018, PCI DSS Level 1, and SOC 1, 2, and 3).”