Security & Trust

Your data is protected by enterprise-grade infrastructure.

MainSquare operates on a platform certified under SOC 2 Type II for Security, Availability, and Confidentiality. This isn't a checkbox. It's audited by Ernst & Young and tested against your data every time you engage with us.

SOC 2 Type II

Platform Certified

AES-256

Encryption at Rest

TLS 256-bit

Encryption in Transit

AWS KMS

Key Management

Semi-Annual

Penetration Testing

How We Protect You

Six controls, working every day

End-to-End Encryption

All data in transit is encrypted using TLS with 256-bit SSL. Data at rest is encrypted using AES-256 with unique per-chunk encryption keys, managed exclusively within AWS Key Management Service. Your data is encrypted before it touches storage — automatically, without any action required from you.

Least-Privilege Access

No one accesses your data without a documented job function and formal manager authorization. Multi-factor authentication (MFA) and SAML-based SSO are required for all production system access. Access rights are reviewed periodically and revoked immediately upon role change or departure.

Isolated, Hardened Infrastructure

Your data lives in a Virtual Private Cloud, logically isolated from other cloud tenants. All servers are hardened per industry best practices and protected by restricted AWS firewall rules. Corporate and production networks are fully segregated — all inter-network traffic travels over encrypted tunnels.

Built for Continuity

Databases are backed up daily with automated restoration testing. A Business Continuity Plan (BCP) maintains backup infrastructure in a separate AWS Availability Zone, designed to keep services running while primary systems are restored. Production is continuously monitored for availability, errors, and anomalies.

Tested Code, Every Deployment

Every code change undergoes peer review, unit testing, and formal approval before deployment. No developer can push their own unapproved changes. Web application architecture follows OWASP guidelines. Semi-annual third-party penetration testing is performed by independent security professionals.

Your Data Stays Yours

Client data is used exclusively to deliver the agreed engagement services. It is never sold, shared, or transferred to third parties without your explicit written consent. Every engagement is governed by a Mutual Confidentiality Agreement executed before work begins.

Common Questions

Security FAQ

MainSquare operates on a platform that holds a SOC 2 Type II certification covering Security, Availability, and Confidentiality. MainSquare is also currently pursuing its own individual SOC 2 compliance certification.

Security questions before you engage? Good. Ask them.

We make our security posture available to clients before work begins — not locked behind a sales cycle. Request our full Data Security & Privacy Overview or connect with your engagement lead directly.

Contact Us

The MainSquare platform operates on Base44, a product of Wix.com Ltd. The SOC 2 Type II audit opinion was issued by Kost Forer Gabbay and Kasierer (Ernst & Young Global Limited) for the period September 1 to November 30, 2025, and covers controls related to the Security, Availability, and Confidentiality trust service criteria as they apply to the Base44 platform. MainSquare makes no independent claims of SOC 2 certification. Security controls are subject to change. For the most current information, contact your MainSquare engagement lead.

Prepared by MainSquare | mainsquare.co | August 2026