Security Policy
The floor, not the upsell
Security is not a feature — it's the floor. Below is what we actually do — encryption in transit and at rest, biometric facility access, regular third-party audits, a vulnerability disclosure program at security@suzko.com — not what we wish were true.
This Security Policy is incorporated into and forms part of our Terms of Service, and your use of SUZKO services is governed by both. Where this document addresses a specific subject, it controls over the Terms of Service to the extent of any conflict on that subject. It describes our practices in good faith; it does not enlarge SUZKO's obligations, create any service-level or contractual guarantee, or grant any rights beyond those set out in the Terms of Service.
Infrastructure Security
Physical Security
Our data centers feature enterprise-grade physical security measures:
- 24/7/365 on-site security personnel
- Biometric access controls and multi-factor authentication
- Video surveillance with extended retention
- Mantrap entry systems
- Visitor logging and escort requirements
- Perimeter fencing and intrusion detection systems
Network Security
We implement multiple layers of network protection:
- Enterprise-grade firewalls with intrusion prevention
- DDoS mitigation with multi-terabit capacity
- Network segmentation and VLANs
- Regular penetration testing and vulnerability assessments
- 24/7 network monitoring and alerting
- BGP route filtering and traffic analysis
Server Security
All servers are hardened according to industry best practices:
- Regular security patches and updates
- Minimal attack surface (unnecessary services disabled)
- Host-based intrusion detection
- Anti-malware and rootkit detection
- Secure boot and firmware integrity verification
- Automated vulnerability scanning
Data Protection
Encryption
| Data State | Encryption Standard |
|---|---|
| Data in Transit | TLS 1.2 / TLS 1.3 |
| Data at Rest | AES-256 |
| Backup Data | AES-256 with separate key management |
| Database Connections | TLS with certificate validation |
Access Controls
- Role-based access control (RBAC) for all systems
- Principle of least privilege enforced
- Multi-factor authentication required for all administrative access
- Regular access reviews and certification
- Privileged access management with session recording
- Automatic account lockout after failed attempts
Data Handling
- Data classification and handling procedures
- Secure data disposal and sanitization
- Encryption key management with hardware security modules
- Regular backup testing and verification
Application Security
Secure Development
Our development practices include:
- Security training for all developers
- Secure coding guidelines and code review
- Static and dynamic application security testing (SAST/DAST)
- Dependency vulnerability scanning
- Security requirements in design phase
- Pre-deployment security review
Customer Account Security
We provide multiple security features for customer accounts:
- Two-factor authentication (TOTP)
- Strong password requirements
- Login attempt monitoring and alerting
- Session management and timeout controls
- API key management with granular permissions
- Activity logging and audit trails
Shared Responsibility
Security is a shared responsibility between SUZKO and you. SUZKO is responsible for the security of the underlying platform and infrastructure described above. You are responsible for security within your own account and workloads, including:
- Safeguarding your account credentials, API keys, and tokens, and enabling the account-protection features we make available (such as two-factor authentication and strong passwords)
- Configuring and maintaining your own access controls, user roles, and permissions, and promptly revoking access you no longer need
- Application-layer security for anything you build, deploy, or host — including secure coding, input validation, secrets management, and third-party dependencies
- Patching, updating, hardening, and monitoring any customer-managed workloads, operating systems, containers, and software
- The lawful, secure handling of the data you upload, process, store, or transmit, including backups you are responsible for maintaining
SUZKO is not responsible for security incidents arising from your acts or omissions, misconfiguration of your services, compromised credentials that were not the result of a failure of our systems, or vulnerabilities in software or content you control.
Operational Security
Personnel Security
- Background checks for all employees
- Security awareness training (initial and ongoing)
- Confidentiality agreements
- Access revocation upon termination
- Regular security policy acknowledgment
Incident Response
We maintain a comprehensive incident response program that includes:
- 24/7 security monitoring and on-call response team
- Documented incident response procedures
- Regular tabletop exercises and drills
- Post-incident analysis and improvement
- Customer notification within 72 hours of confirmed breach
- Coordination with law enforcement when appropriate
Business Continuity
- Redundant systems and failover capabilities
- Regular backup and disaster recovery testing
- Geographically distributed infrastructure
- Documented recovery procedures with defined RTOs and RPOs
Compliance and Certifications
We align our security practices with industry standards and frameworks:
- SOC 2 Type II (annual audit)
- ISO 27001 aligned practices
- PCI DSS compliant payment processing (via Stripe)
- GDPR and data protection regulations
- HIPAA-eligible infrastructure available upon request
Important: Security is provided on a commercially reasonable basis. No system, product, or method of transmission or storage is 100% secure, and we cannot guarantee that our services or the data they contain will be free from unauthorized access, compromise, or loss. The certifications, attestations, and alignment statements described above reflect the state of our program at the time of the relevant audit or assessment and are subject to change. They do not constitute a warranty or guarantee of invulnerability, do not certify the security of your own account, applications, or workloads, and create no service-level, indemnification, or contractual guarantee beyond what is expressly stated in our Terms of Service. HIPAA-eligible infrastructure and PCI-related capabilities support your compliance efforts but do not by themselves make your use of our services compliant; you remain responsible for configuring and operating your environment in a compliant manner.
Vulnerability Disclosure Program
Reporting Security Issues
We appreciate the security research community's efforts in helping keep our services secure. If you discover a security vulnerability, please report it to us responsibly.
Report vulnerabilities to: security@suzko.com
Please include:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact assessment
- Any proof-of-concept code (if applicable)
- Your contact information for follow-up
Our Commitment
When you report a vulnerability to us, we will:
- Acknowledge receipt within 24 hours
- Provide an initial assessment within 5 business days
- Keep you informed of our progress
- Credit you in our security acknowledgments (if desired)
- Not take legal action against good-faith researchers
Scope
The following are in scope for our vulnerability disclosure program:
- suzko.com and all subdomains
- Customer portal and API
- Control panel integrations
The following are out of scope:
- Third-party services and integrations
- Social engineering attacks
- Physical attacks
- Denial of service attacks
- Customer data or systems
Safe Harbor
SUZKO authorizes good-faith security research and testing conducted within the scope defined above, and we will not pursue or support legal action against researchers for such activity, provided you comply with all of the following conditions at all times:
- You limit your testing strictly to systems and endpoints listed as in scope, and you stop immediately if you encounter anything out of scope.
- You do not access, download, exfiltrate, modify, or destroy data that does not belong to you, and you do not violate the privacy of any user; if you inadvertently encounter another party's data, you stop, do not retain or share it, and report it promptly.
- You do not degrade, disrupt, or interrupt our services or those of our customers — no denial-of-service, resource-exhaustion, spam, social engineering, or physical attacks.
- You comply with all applicable laws and regulations.
- You practice coordinated disclosure: you report the issue to us privately, give us a reasonable opportunity to investigate and remediate, and do not publicly disclose any vulnerability or related details before we have confirmed it is resolved and agreed to disclosure.
This is a vulnerability disclosure program, not a paid bug bounty. No monetary reward, bounty, or other compensation is offered or implied for any report, and submission of a report creates no obligation on SUZKO's part beyond what is stated in this policy. We may recognize researchers in our acknowledgments where they wish to be credited.
Activity that falls outside the stated scope or that violates any of the conditions above is not authorized, is not covered by this safe harbor, and may be handled at our discretion, including reporting to the appropriate authorities. SUZKO reserves the right to modify the scope and terms of this program at any time, and is under no obligation to respond to, act on, or acknowledge out-of-scope reports.
Security Updates
We continuously improve our security posture. Major security updates and advisories are communicated through:
- Service status page notifications
- Email to affected customers
- In-portal announcements
Contact Information
For security-related inquiries, please contact us at:
SUZKO, LLC
security@suzko.com (Security Issues)
legal@suzko.com (General Legal)
+1 (888) 819-1699 Toll Free (US & Canada)
+1 (317) 854-5007 Headquarters (US Only)
312 N Green St, Suite D
Crawfordsville, Indiana
47933, United States
Last updated: July 16, 2026