Encrypted, access-controlled and monitored by default.
missionX runs entirely on Google Cloud Platform and MongoDB Atlas. We don't operate our own data centers or maintain a home-grown security stack, we inherit the same infrastructure controls used to run some of the most regulated workloads in the world.
Every layer, network, compute and database, is encrypted in transit and at rest, with access locked down to what's needed and nothing more.

Encryption, in transit and at rest
Every connection to missionX is encrypted with TLS 1.2+, terminated at Google Cloud's load balancers before traffic ever reaches the application layer.
Data at rest is encrypted with AES-256 at both the infrastructure level, via Google Cloud's default disk and storage encryption, and the database level, via MongoDB Atlas's encrypted storage engine. Backups carry the same encryption, whether in flight or at rest.
- TLS 1.2+ enforced on every connection
- AES-256 encryption at rest, infrastructure and database
- Encryption keys managed and rotated via Google Cloud KMS
- Encrypted, automated backups with point-in-time recovery
MFA and access control
Nothing in missionX has to rely on a password alone. Multi-factor authentication is available on user and administrator accounts, alongside Microsoft and SAML single sign-on for enterprise identity providers.
Internally, our own team authenticates through the same identity layer, with MFA available to protect access into production systems.
- Multi-factor authentication available on user and admin accounts
- Microsoft and SAML single sign-on (SSO)
- Granular, role-based organization permissions
- MFA available to protect internal access
Google Cloud Platform
missionX is hosted on Google Cloud, the same infrastructure Google runs its own products on, independently audited against ISO 27001, SOC 1, SOC 2, SOC 3 and other global standards.
MongoDB Atlas
Our operational data lives in MongoDB Atlas, run as a fully managed, security-hardened database layer rather than a self-hosted instance.
- Encrypted storage engine (AES-256) for all data at rest
- TLS-encrypted connections between application and database
- Network isolation via VPC peering and private endpoints, no public database access
- Fine-grained, role-based database access control (RBAC)
- Continuous monitoring and audit logging of database activity
- Automated, encrypted backups with point-in-time recovery
Internal processes
Infrastructure is only half of it. The rest comes down to how we work internally, day to day.
- Least-privilege access, only what's needed, only for as long as it's needed
- Separate staging and production environments
- Code review required before anything reaches production
- Regular access reviews and credential rotation
- Centralized logging and monitoring across environments
- An incident response process for identifying and containing issues quickly
Questions about our security?
For anything not covered here, or for security documentation to support your own review process, reach out and we'll walk you through it.
