Last Updated: January, 2026
Owner: Security/Compliance Team Email, [email protected]
At ParkingPass.com, safeguarding our customers’ data and maintaining your trust is our top priority. We employ rigorous security measures, continuous monitoring, and industry-standard compliance frameworks to ensure your data remains safe, secure, and available.
1. Compliance & Certifications
We validate our security posture through independent, third-party audits and continuous compliance monitoring.
-
SOC 2 Type I / Type II: We are actively undergoing/have achieved SOC 2 compliance, evaluating our controls across Security, Availability, and Confidentiality. (Our report is available to prospects and customers under NDA).
-
CCPA: We are fully committed to data privacy and comply with global regulations regarding data protection, user consent, and data deletion rights.
-
Continuous Monitoring: We use automated platforms (like Vanta) to monitor our compliance posture 24/7/365, ensuring our controls never drift.
2. Data Protection & Encryption
We ensure your data is protected both when it is moving across the internet and when it is stored on our systems.
| Data State | Protocol / Standard | Description |
| In Transit | HTTPS / TLS 1.3 (or 1.2) | All data sent between your browser and our servers is encrypted using modern, secure cryptographic protocols. |
| At Rest | AES-256 Encryption | All customer data, backups, and databases are encrypted at rest using industry-standard AES-256 encryption. |
| Key Management | Cloud KMS / Key Rotation | Encryption keys are securely managed and automatically rotated using cloud-native key management services. |
3. Infrastructure & Network Security
Our application is hosted in a world-class, highly secure environment.
-
Cloud Hosting: We host our infrastructure with Amazon Web Services, utilizing data centers that are certified ISO 27001, SOC 2, and PCI-DSS compliant.
-
Network Isolation: Our production environment is isolated within a Virtual Private Cloud (VPC). Strict firewall rules and Security Groups restrict inbound and outbound traffic.
-
High Availability: We utilize multi-Availability Zone (AZ) deployments and automated scaling to ensure our services remain resilient against hardware failures or localized outages.
4. Access Control & Identity Management
We strictly adhere to the principle of least privilege, ensuring team members only have access to the data necessary for their roles.
-
Multi-Factor Authentication (MFA): MFA is strictly enforced across all internal company accounts, cloud providers, and third-party tools.
-
Single Sign-On (SSO): We utilize centralized identity providers to manage and provision employee access securely.
-
Access Reviews: Employee access rights to production environments and critical tools are reviewed quarterly to ensure alignment with current roles.
5. Secure Software Development
Security is baked into our software development lifecycle (SDLC) from day one.
-
Code Reviews: All code changes require mandatory peer review and automated testing before being merged into production.
-
Vulnerability Scanning: Automated Static Application Security Testing (SAST) and Dependency Scanning are integrated into our CI/CD pipelines to catch security flaws before deployment.
-
Penetration Testing: We engage independent, certified security firms at least annually to perform comprehensive penetration testing on our applications and infrastructure.
6. Incident Response & Business Continuity
We are prepared for the unexpected and maintain clear playbooks to handle security events.
-
24/7 Monitoring & Alerting: We use centralized logging and security information event management (SIEM) tools to monitor for anomalies and potential threats.
-
Incident Response Team: We maintain a dedicated incident response plan. In the event of a suspected data breach, our team is equipped to isolate, investigate, and remediate threats swiftly.
-
Backups & Recovery: Production data is backed up daily, encrypted, and stored in physically separate locations. We regularly test our recovery processes to ensure minimal Recovery Time Objectives (RTO).
Vulnerability Disclosure & Contact
If you believe you have discovered a security vulnerability in our platform, please report it immediately to [email protected]. We take all reports seriously and appreciate your help in keeping our community safe.
