Graphly Data Security Statement (DSS)
Last Updated: August 2026
Overview
This Statement describes the technical and organizational measures (“TOMs”) Graphly maintains to protect Client Personal Data, and constitutes Annex II (Technical and Organizational Measures) to the Standard Contractual Clauses incorporated into Graphly’s Data Processing Addendum.
Hosting and infrastructure
Graphly operates entirely on managed, certified cloud infrastructure. Application workloads run on Laravel Cloud (SOC 2 Type 2 attested for Security, Confidentiality, and Availability) on Amazon Web Services. Databases run on Amazon Aurora (multi-AZ, automated failover) and object storage on Amazon S3 (ISO 27001/27017/27018, SOC 1/2/3).
All public traffic is served through an edge network with a web application firewall (OWASP Core Ruleset) and DDoS protection. Graphly maintains no self-managed servers: there is no SSH surface or hand-configured operating system anywhere in production, and every deployment is an immutable build.
Encryption
In transit: TLS 1.2+ on all public endpoints; HTTPS-only for all third-party API integrations (CRM access via OAuth 2.0).
At rest: AES-256 encryption for databases (AWS KMS-managed keys) and backup archives (S3 server-side encryption).
Application layer: encrypted and signed session cookies; passwords hashed with bcrypt; application secrets stored exclusively in the hosting platform’s encrypted environment store and never in source control (enforced by automated tests).
Tenant isolation and access control
Each client’s mirrored CRM data resides in a dedicated per-client database schema — tenant isolation is physical, not merely row-level. Application access is governed by role-based access control and per-account authorization on every route; partner (agency) access is scoped to the accounts the partner manages. Internal production access follows strict least privilege and is limited to named engineering personnel; there is no standing third-party or contractor access.
Multi-factor authentication is enforced on all infrastructure and administrative accounts (cloud provider, hosting platform, source control, DNS, monitoring). Database network access is restricted by firewall allowlist to authorized application egress.
Audit logging and monitoring
An application audit trail records authentication events (successful and failed logins, logouts, password resets), staff and partner account access across all access portals (with the acting user recorded), access-grant changes (invitations, acceptances, removals), bulk data exports, integration credential changes, and account lifecycle events – each with actor, IP address, and user agent, retained for 12 months.
Infrastructure and access logs are centralized by the hosting platform. Application errors are monitored in real time with alerting; scheduled-job execution is heartbeat-monitored.
Backup and disaster recovery
Two independent backup layers protect Client Personal Data: continuous point-in-time recovery on the primary database (14-day window, restorable to any second) and nightly encrypted backup archives stored in a separate AWS region from the primary database (90-day automated retention).
The database runs multi-AZ with automated failover, and cross-region recovery capability has been exercised live in production. Recovery objectives: near-zero RPO; RTO of four hours or less for full recovery including regional failure.
Secure development and change management
Every production change passes mandatory code review and a full automated test suite gate before deployment; deployments are automated and reproducible.
The application runs on current framework and runtime versions, with dependencies patched continuously.
Operating system, runtime, and database engine patching is handled by the managed platforms; automatic minor-version upgrades are enabled on the database.
Data lifecycle
Client Personal Data is retained only for the duration of the subscription and deleted on a defined automated schedule after termination (mirrored CRM data within 45 days; remaining account data within 100 days; backup copies expire on rolling windows not exceeding 90 days thereafter), or earlier upon written request. Trial-account data is purged automatically after trial expiry. Audit logs are pruned at 12 months. Website visit data from the legacy tracking feature is retained for 26 months and purged automatically in rolling batches.
Incident response
Graphly maintains a documented incident response process: detection (monitoring and alerting) → triage → containment → eradication → recovery → notification → post-incident review with corrective actions.
Confirmed Personal Data Breaches are notified to affected clients without undue delay and in any event within 72 hours of confirmation, including the nature and scope of the incident, affected data categories, measures taken, and a named contact.
The audit trail supports precise scoping of affected accounts and data during incident assessment.
Personnel
All personnel with access to Client Personal Data are bound by confidentiality obligations. Access grants are administered by a single accountable owner; role changes or departures result in immediate credential revocation and rotation of shared secrets.
Subprocessors
Graphly engages the subprocessors listed at graphly.io/legal/subprocessors, each bound by written data protection obligations substantially similar to Graphly’s own commitments and selected with regard to independent certifications (SOC 2, ISO 27001). Clients receive at least 30 days’ advance notice of subprocessor changes.
Contact Information
Questions regarding privacy, security, or data protection may be directed to:
Dustin Lunt
Data Protection Officer
dustin@graphly.io
For additional information regarding privacy and compliance, please visit: