Acryl encrypts data at rest and in transit for all of our customers. We use tools like Amazon Web Service’s Key Management System (KMS) to manage encryption keys using hardware security modules for maximum security in line with industry best practices.
Acryl regularly engages some of the industry’s best application security experts for third-party penetration tests. Our penetration testers evaluate the source code, running application, and the deployed environment. Acryl also uses high-quality static analysis tooling provided by GitHub Advanced Security such as CodeQL, Secrets Scanner, and Dependabot to secure our product at every step of the development process. Including our own use of a wide range of tooling such as TruffleHog.
Acryl uses Amazon Web Services to host our application. We make full use of the security products embedded within the AWS ecosystem, including KMS, GuardDuty, and Inspector. Our containerized platform includes security scanning of containers, use of SSM services to apply and manage OS level CVEs and constant monitoring and alerting driven from various AWS as well as in-house tooling. Our infrastructure utilizes IaC and pre-checks executed before we adjust our infrastructure are reviewed and tested at all times.