Security & Trust
MainSquare operates on a platform certified under SOC 2 Type II for Security, Availability, and Confidentiality. This isn't a checkbox. It's audited by Ernst & Young and tested against your data every time you engage with us.
SOC 2 Type II
Platform Certified
AES-256
Encryption at Rest
TLS 256-bit
Encryption in Transit
AWS KMS
Key Management
Semi-Annual
Penetration Testing
How We Protect You
All data in transit is encrypted using TLS with 256-bit SSL. Data at rest is encrypted using AES-256 with unique per-chunk encryption keys, managed exclusively within AWS Key Management Service. Your data is encrypted before it touches storage — automatically, without any action required from you.
No one accesses your data without a documented job function and formal manager authorization. Multi-factor authentication (MFA) and SAML-based SSO are required for all production system access. Access rights are reviewed periodically and revoked immediately upon role change or departure.
Your data lives in a Virtual Private Cloud, logically isolated from other cloud tenants. All servers are hardened per industry best practices and protected by restricted AWS firewall rules. Corporate and production networks are fully segregated — all inter-network traffic travels over encrypted tunnels.
Databases are backed up daily with automated restoration testing. A Business Continuity Plan (BCP) maintains backup infrastructure in a separate AWS Availability Zone, designed to keep services running while primary systems are restored. Production is continuously monitored for availability, errors, and anomalies.
Every code change undergoes peer review, unit testing, and formal approval before deployment. No developer can push their own unapproved changes. Web application architecture follows OWASP guidelines. Semi-annual third-party penetration testing is performed by independent security professionals.
Client data is used exclusively to deliver the agreed engagement services. It is never sold, shared, or transferred to third parties without your explicit written consent. Every engagement is governed by a Mutual Confidentiality Agreement executed before work begins.
Common Questions
MainSquare operates on a platform that holds a SOC 2 Type II certification covering Security, Availability, and Confidentiality. MainSquare is also currently pursuing its own individual SOC 2 compliance certification.
We make our security posture available to clients before work begins — not locked behind a sales cycle. Request our full Data Security & Privacy Overview or connect with your engagement lead directly.
The MainSquare platform operates on Base44, a product of Wix.com Ltd. The SOC 2 Type II audit opinion was issued by Kost Forer Gabbay and Kasierer (Ernst & Young Global Limited) for the period September 1 to November 30, 2025, and covers controls related to the Security, Availability, and Confidentiality trust service criteria as they apply to the Base44 platform. MainSquare makes no independent claims of SOC 2 certification. Security controls are subject to change. For the most current information, contact your MainSquare engagement lead.
Prepared by MainSquare | mainsquare.co | August 2026