Your data security is our top priority. Learn how we protect your information.
All data encrypted at rest with AES-256 and in transit with TLS 1.2+
Hosted on AWS with SOC 2 Type II certified infrastructure
Built with privacy-first principles aligned with GDPR and CCPA
Role-based access control with optional two-factor authentication
Automated monitoring with alerting for security events
Automated encrypted backups with 35-day point-in-time recovery
We use industry-standard encryption to protect your data at every stage:
Selmi is hosted on Amazon Web Services (AWS), a SOC 2 Type II certified cloud provider:
We implement access controls to help prevent unauthorized access:
Our APIs are designed with security best practices:
We design our systems with privacy regulations in mind:
We maintain visibility into our systems to detect and respond to issues:
We work with trusted third-party service providers to deliver our service. These providers process data on our behalf:
| Service Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting, database, storage, email | United States |
| Stripe | Payment processing | United States |
| Apple | Apple Wallet pass delivery | United States |
| Google Wallet pass delivery | United States |
If you discover a security vulnerability, please report it to us responsibly.
We appreciate responsible disclosure and will work to address verified vulnerabilities promptly.
Last updated: February 2026