Security & Access

Infrastructure

Our service is built using the Amazon Web Services (AWS) cloud. AWS offers robust security mechanisms to protect our infrastructure.

Our networking infrastructure (routers, load balancers, DNS servers,…) are all managed by AWS.

All communications are performed through end-to-end HTTPS encryption.

Access to our network is strictly controlled using a VPN with network access control lists (ACL) and IP whitelisting.

Our inbound and outbound network traffic is monitored and controlled using firewalls and IP whitelisting.

We are using an industry-leading solution to mitigate our risk of Distributed Denial of Service (DDoS).

We are using solutions to monitor the performance of our platform and log errors in our service.

We commit to full transparency on all outages and service degradation. You can follow our system status in real time on our public status page.

We are using separate environments for testing and production.

Application Security

We are following OWASP security best practices to protect our solution.

We are restricting access to production data to authorized staff members only and protecting it by 2FA, VPN access, and IP Whitelisting.

We are reviewing our code systematically for security vulnerabilities. We welcome responsible disclosure of vulnerabilities. We are strictly controlling who has access to our source code.

We are monitoring and updating our dependencies to make sure none of them has know vulnerabilities.

We are regularly performing automated penetration tests against all our endpoints.

In-depth manual PenTests are performed by independent third parties on a regular basis. You can request access to the latest PenTest reports here.

Service Levels

Traditionally, Refiner had an uptime of 99.9% or higher. One of our top priorities is to provide uninterupted services at all times. You can follow our system status in real time on our public status page.

Data Encryption

All data coming to or sending from our infrastructure is encrypted in transit using Transport Layer Security (TLS 1.2). All data in our system is encrypted at rest using AES 256-bit encryption algorithm.

Authentication & Access Control

Refiner supports SAML 2.0 Single Sign-On (SSO) for secure and centralized authentication.

With SAML SSO, you can:

  • Manage user access through your identity provider (IdP)
  • Enforce company-wide security policies (e.g. MFA)
  • Simplify user provisioning and access management

SAML SSO is recommended for teams with advanced security or compliance requirements. Please contact us to set up SAML SSO on your account.

Employees & Contractors

We require all employees and contractors to sign a confidentiality agreement and comply with our cybersecurity policy. We are reviewing our cyber security policy every quater and train our team on security regularly.

We enforce a device management policy (password strength and rotation, lock screen when leaving the desk, disk encryption, remote lock).

Our employees and contractors must report all actual or suspected IT security incidents.

By default, our employees and contractors don’t have access to user data. Exceptions can be made for customer support.

Bug Bounty Program

Refiner supports responsible disclosure and values the contributions of the security research community. If you discover a potential vulnerability, please report it to us with sufficient detail to allow for timely investigation and remediation.

Was this helpful? Let us know with a quick a vote