Legal / Security
Security Overview
Last Updated April 30, 2026
This page summarizes how FeedBlox protects data processed through the hosted platform and embeddable widget. It does not create contractual commitments beyond those in the Terms of Service, is not a substitute for a completed security questionnaire, and is not a warranty or certification. FeedBlox is not currently SOC 2, ISO 27001, or HIPAA certified. We do not accept protected health information (PHI).
Account Protection
We support password-based and federated sign-in. Passwords are stored using a memory-hard hashing function. Sessions use HTTP-only cookies. Treat your password, OAuth account, and embed tokens as the trust anchors for your workspace.
Data in Transit and at Rest
Public endpoints require TLS. Customer data is stored in managed databases with encryption at rest. Encrypted backups are taken on a rolling schedule.
Network and Platform
The Service runs on cloud infrastructure with logically segmented production environments, restricted ingress, and managed secrets handling. Production deployments come from version-controlled source.
Access Control
Access to production systems is restricted to personnel with a documented business need, granted on a least-privilege basis, and revoked when no longer required.
Logging and Monitoring
We log authentication, administrative actions, and anomalous request patterns, and monitor error rates and availability.
Incident Response
If we confirm a security incident affecting your data, we will notify affected account owners without unreasonable delay and describe what we know, what we are doing, and what you should do.
Report a Vulnerability
Email security@feedblox.net.
Related: Privacy Policy and Subprocessors.