Launch

Encrypted, access-controlled and monitored by default.

missionX runs entirely on Google Cloud Platform and MongoDB Atlas. We don't operate our own data centers or maintain a home-grown security stack, we inherit the same infrastructure controls used to run some of the most regulated workloads in the world.

Every layer, network, compute and database, is encrypted in transit and at rest, with access locked down to what's needed and nothing more.

Encryption, in transit and at rest

Every connection to missionX is encrypted with TLS 1.2+, terminated at Google Cloud's load balancers before traffic ever reaches the application layer.

Data at rest is encrypted with AES-256 at both the infrastructure level, via Google Cloud's default disk and storage encryption, and the database level, via MongoDB Atlas's encrypted storage engine. Backups carry the same encryption, whether in flight or at rest.

  • TLS 1.2+ enforced on every connection
  • AES-256 encryption at rest, infrastructure and database
  • Encryption keys managed and rotated via Google Cloud KMS
  • Encrypted, automated backups with point-in-time recovery

MFA and access control

Nothing in missionX has to rely on a password alone. Multi-factor authentication is available on user and administrator accounts, alongside Microsoft and SAML single sign-on for enterprise identity providers.

Internally, our own team authenticates through the same identity layer, with MFA available to protect access into production systems.

  • Multi-factor authentication available on user and admin accounts
  • Microsoft and SAML single sign-on (SSO)
  • Granular, role-based organization permissions
  • MFA available to protect internal access

Google Cloud Platform

missionX is hosted on Google Cloud, the same infrastructure Google runs its own products on, independently audited against ISO 27001, SOC 1, SOC 2, SOC 3 and other global standards.

01
Network isolation
Every environment runs in its own VPC, with Cloud Armor filtering traffic and mitigating DDoS at the edge.
02
Identity & IAM
Fine-grained Cloud IAM roles govern exactly which people and services can touch which resource.
03
Key management
Cloud KMS handles encryption key generation, rotation and access, kept separate from application code.
04
Redundancy
Multi-zone deployment and automated failover keep the platform available if a zone goes down.
05
Hardened by default
Shielded VMs, encrypted-by-default storage and a security team that patches infrastructure so we don't have to.

MongoDB Atlas

Our operational data lives in MongoDB Atlas, run as a fully managed, security-hardened database layer rather than a self-hosted instance.

  • Encrypted storage engine (AES-256) for all data at rest
  • TLS-encrypted connections between application and database
  • Network isolation via VPC peering and private endpoints, no public database access
  • Fine-grained, role-based database access control (RBAC)
  • Continuous monitoring and audit logging of database activity
  • Automated, encrypted backups with point-in-time recovery

Internal processes

Infrastructure is only half of it. The rest comes down to how we work internally, day to day.

  • Least-privilege access, only what's needed, only for as long as it's needed
  • Separate staging and production environments
  • Code review required before anything reaches production
  • Regular access reviews and credential rotation
  • Centralized logging and monitoring across environments
  • An incident response process for identifying and containing issues quickly

Questions about our security?

For anything not covered here, or for security documentation to support your own review process, reach out and we'll walk you through it.