Security
Citations.io is a trading style of NE26 Limited, a company registered in England and Wales (company number 16030871) with its registered office at First Floor Office, 3 Hornton Place, London, W8 4LZ, United Kingdom.
1.Our security program
Citations.io operates a written information-security program aligned with the principles of ISO/IEC 27001 and the AICPA Trust Services Criteria. The program is owned by our engineering leadership, reviewed at least annually, and applied to all employees, contractors and sub-processors who access customer data.
2.Encryption
- In transit: TLS 1.2 or higher for all connections to the Service. HSTS is enabled on the public website.
- At rest: AES-256 on managed database storage and object storage.
- Secrets: API keys and credentials are stored in a managed secrets store and rotated on a documented schedule.
3.Access control
- Role-based access control with least-privilege defaults.
- Multi-factor authentication enforced for all administrative access to production systems and source-code repositories.
- Production access is limited to a small group of engineers with a documented business need and is logged.
- SSO (Google) supported for customer accounts; SAML/SCIM available on Enterprise plans.
4.Network and infrastructure
- Hosted on Cloudflare's edge network with DDoS protection and Web Application Firewall.
- Managed Postgres on Supabase (EU region) with automated backups and point-in-time recovery.
- Network segmentation between public, application and data tiers.
- Centralised logging and continuous monitoring for anomalous activity.
5.Secure development lifecycle
- All changes go through code review and automated testing before merge.
- Dependency scanning, static analysis and secret scanning run on every commit.
- Production deploys are auditable and reversible.
- Engineers receive annual secure-development and privacy training.
6.Backups and business continuity
- Database backups are taken continuously and retained for at least 7 days; daily snapshots are retained for 30 days.
- Recovery procedures are tested annually with documented RTO and RPO objectives.
- Critical infrastructure is multi-region or multi-AZ for resilience.
7.Incident response
We maintain a documented incident-response plan covering detection, containment, eradication, recovery and post-incident review. Affected customers are notified of confirmed personal data breaches without undue delay and within 72 hours, as required by our DPA.
8.Responsible disclosure
Security researchers are invited to report suspected vulnerabilities to security@citations.io. Please follow the guidance in our Acceptable Use Policy - we will not pursue legal action against good-faith research that complies with that guidance, and we will credit researchers (with permission) once a fix is shipped.
9.Compliance and certifications
Privacy laws
The Service is designed to support customer compliance with the UK GDPR, EU GDPR and California Consumer Privacy Act (as amended by the CPRA). See our Privacy Policy and DPA.
SOC 2 / ISO 27001
SOC 2 Type II is on our compliance roadmap. While we are not yet certified, the underlying controls described above are in place. Customers under NDA may request our current security questionnaire and architecture overview.
Write to security@citations.io and we will respond within 30 days, or sooner where required by law.