Security Statement
Our Approach to Platform Security and Data Protection
Security at a Glance
| • Hosted on Amazon Web Services (AWS) | • Continuous security monitoring |
| • Annual independent penetration testing by Cobalt | • Point in Time Recovery (PITR) for database data |
| • AES 256 encryption at rest using AWS Key Management Service (KMS) | • Encrypted nightly backups replicated to a secondary AWS region |
| • TLS 1.2 or higher encryption in transit | • Automated weekly backup restore testing |
| • Multi Factor Authentication (MFA) required for every account | • Malware scanning for support ticket attachments |
| • Microsoft Single Sign On (SSO) | • Comprehensive audit logging |
| • Role based access control | • Documented security incident response process |
| • Database level tenant isolation | • Secure management of production secrets and credentials |
| • Web Application Firewall (WAF) and DDoS protection |
Security is fundamental to how SecuVeo is designed and operated. As a platform built specifically for Managed Service Providers (MSPs), we understand the importance of protecting MSP data while maintaining a secure, reliable and accountable service.
SecuVeo uses multiple layers of technical, operational and administrative controls to help safeguard MSP information. We continually review and strengthen these controls as the platform and cybersecurity landscape evolve.
Our security program includes secure software development practices, continuous monitoring, independent penetration testing, encrypted backups, disaster recovery capabilities and regular review of platform security controls.
Infrastructure & Hosting
SecuVeo is hosted on Amazon Web Services (AWS) using hardened infrastructure designed to provide a secure, reliable and highly available platform.
The platform operates in the US East (N. Virginia) region. Encrypted backup copies are replicated to US West (Oregon) for disaster recovery, with an additional read only report archive stored in US East (Ohio).
SecuVeo is operated by MSP SecureView LLC FZ, a UAE company, and the platform is hosted in the United States. Where personal data is transferred internationally, transfers are covered by the international data transfer terms in our Data Processing Agreement and applicable data protection requirements, alongside the technical measures described in this statement, including encryption in transit and at rest, tenant isolation and role based access control. Malware scanning of uploaded attachments takes place in the United Kingdom.
All communication with SecuVeo is encrypted using HTTPS with TLS 1.2 or higher. Older protocols are refused.
Data is encrypted at rest using industry standard AES 256 encryption with AWS Key Management Service (KMS).
Authentication & Access Control
SecuVeo supports Microsoft Single Sign On (SSO) and requires Multi Factor Authentication (MFA) for every user account.
Users signing in with an email address and password must enroll an authenticator application before accessing the platform.
Users signing in with Microsoft are protected by their organization’s Microsoft 365 authentication and MFA policies and are not prompted for an additional SecuVeo authentication code.
Access is controlled through role based permissions so users can access only the functionality appropriate to their role.
Data is isolated at the database level using Row Level Security (RLS), helping ensure each MSP can access only its own information.
Third Party Integration Security
SecuVeo follows the principle of least privilege when connecting to third party platforms. Integrations are designed to use only the permissions required to provide their intended functionality, rather than requiring unrestricted administrative access.
For PSA integrations, SecuVeo uses granular permissions and dedicated integration accounts where available to limit access to the data and actions required by the integration. Detailed permission requirements for each integration are documented in the SecuVeo Support Manual.
Secure Development & Platform Security
Security is integrated throughout the development and ongoing operation of SecuVeo.
We follow secure software development practices, apply security updates promptly and continuously review the platform for security improvements.
Security monitoring and protection include:
- Continuous automated vulnerability scanning
- Threat detection and intrusion monitoring
- Web Application Firewall (WAF)
- Distributed Denial of Service (DDoS) protection
- Configuration monitoring
- Comprehensive audit logging
Operating system security updates are applied automatically, while platform monitoring and security alerts operate continuously to help identify and respond to potential security events.
SecuVeo also monitors relevant security advisories, product updates and release notes from key technology providers, including Microsoft, HaloPSA and ConnectWise PSA. Changes that may affect security, compatibility or service reliability are reviewed and addressed where necessary.
Security Incident Response
SecuVeo maintains a documented security incident response process for identifying, investigating, containing and responding to potential security incidents.
Security events are monitored and escalated as appropriate to support timely investigation and response.
Secrets & Credential Management
Production secrets, API credentials and other sensitive application credentials are securely stored and access controlled.
Sensitive credentials are not stored in application source code, and access is restricted to authorized systems and personnel.
File Security
Support ticket attachments are stored within encrypted private storage using randomized filenames and time limited download links.
Uploads are restricted to supported document and image formats. Executables, scripts and archive files are not permitted, and attachments are limited to 25 MB.
All support ticket attachments are automatically scanned for malware before becoming available within the platform. Files remain quarantined until they successfully pass malware scanning. Files that fail scanning are rejected and cannot be attached to support tickets.
Backups & Business Continuity
Data is protected through multiple independent, encrypted backup and recovery mechanisms.
The SecuVeo database is protected by Point in Time Recovery (PITR), providing the ability to restore database data to a specific point in time within the configured recovery window.
Encrypted database backups are also performed nightly and retained for six months. Backup integrity is verified through automated weekly restore testing to confirm that backups can be successfully recovered.
Report PDFs are archived independently every night and retained for two years.
Monthly encrypted infrastructure snapshots, retained for six months, provide an additional layer of disaster recovery protection.
Backups are replicated to a secondary AWS region using separate encryption keys, helping protect secondary backup copies from an event affecting the primary region.
Independent Security Testing
SecuVeo undergoes independent third party penetration testing by Cobalt, an application security company.
Between August and September 2026, Cobalt conducted an independent penetration test of the SecuVeo web application and APIs. The assessment included manual testing of authentication, authorization, business logic, tenant isolation and other application security controls.
Findings identified during the assessment were reviewed and remediated as appropriate, with remediation independently retested and verified by Cobalt.
SecuVeo undergoes independent penetration testing at least annually and following material changes where appropriate.
Auditability & Accountability
SecuVeo maintains comprehensive audit records to support transparency and accountability.
Administrative actions, user activity, report delivery, disclaimer acknowledgements and key platform events are recorded within the platform, providing MSPs with an audit trail of important client interactions and administrative activity.
Audit records are append only and cannot be altered or deleted through the application.
Responsible Disclosure
We welcome reports of potential security vulnerabilities from MSPs and security researchers.
If you believe you have identified a security issue within SecuVeo, please contact us at security@secuveo.com.
We will acknowledge receipt of responsible disclosures and investigate them promptly.
Our Commitment
Security is an ongoing process.
We continuously review and strengthen the platform, invest in independent security testing, monitor emerging threats and evolve our security controls to help protect MSPs and their data.
Last Reviewed: September 2026