Trust Center

Security & Compliance

We take the security of your data and infrastructure seriously. Here's exactly what we do to protect you.

Encryption in Transit

All traffic between your client and MockRoute is encrypted with TLS 1.2+. HTTP connections are permanently redirected to HTTPS.

Password Security

Passwords are hashed using bcrypt with a work factor of 12. We never store plaintext passwords and enforce minimum complexity requirements.

Endpoint Isolation

Each endpoint is scoped to its owner. Subdomains are validated against ownership before any response is served. Cross-tenant access is architecturally impossible.

Data Minimisation

We collect only what is necessary to operate the service. Request log bodies are stored only for configured retention periods and purged automatically.

Access Logging

Administrative access to infrastructure is logged and audited. We alert on anomalous access patterns and conduct regular access reviews.

Vulnerability Disclosure

Found a security issue? Please report it responsibly to security@mockroute.app. We aim to acknowledge reports within 24 hours and resolve critical issues within 72 hours.

Infrastructure Overview

Hosting
Cloud infrastructure with automatic failover and 99.9% uptime SLA
Database
Encrypted at rest. Automated daily backups retained for 30 days.
CDN & DDoS Protection
All endpoints sit behind a CDN with automatic DDoS mitigation
Rate Limiting
Configurable per-endpoint rate limiting to prevent abuse
Dependency Auditing
Dependencies audited weekly for known CVEs using automated tooling

Report a Security Issue

We operate a responsible disclosure programme. If you discover a vulnerability, please email security@mockroute.app with details. Please do not publicly disclose issues until we have had a chance to address them.

Contact Security Team