Security and privacy at Slung

Last updated: August 5, 2026

Security is foundational to how we build Slung. Helping customers underwrite with confidence starts with protecting the data and systems they entrust to us.

Security overview

Slung protects customer information through administrative, technical, and organizational safeguards. Security is built into how we design, operate, and improve the platform — from encryption and network controls to access management, monitoring, and incident response.

Our approach follows least privilege, defense in depth, and continuous improvement. We monitor controls on an ongoing basis and update this page as our practices, audits, and policies evolve.

Data encryption

Data in transit

Customer-facing and API traffic is protected with HTTPS using TLS 1.2 or higher. HTTP requests to our application load balancer are redirected to HTTPS. Content delivered through CloudFront requires modern TLS.

Data at rest

Production databases, object storage, automated database backups and snapshots, and application caches are encrypted at rest. Production Aurora PostgreSQL uses AWS KMS–managed encryption. Amazon S3 buckets that store customer and application data use server-side encryption (AES-256). ElastiCache Redis is encrypted at rest.

Secrets and credentials

Application secrets and credentials are stored in AWS Secrets Manager and injected into runtime environments. Secrets are not committed to source control.

Infrastructure security

Slung runs on Amazon Web Services (AWS). Production application workloads run on Amazon ECS with AWS Fargate. Production data is stored in Amazon Aurora PostgreSQL. Customer uploads and static assets are stored in Amazon S3 and delivered via Amazon CloudFront where applicable.

Network access is controlled with VPC security groups so that databases and caches are not exposed directly to the public internet. Public ingress is limited to HTTPS (and HTTP only for redirect to HTTPS). A regional AWS WAF is associated with the production application load balancer. We review firewall rulesets at least annually.

We maintain logging and monitoring across the environment, including AWS CloudTrail for API activity, Amazon GuardDuty for threat detection, CloudWatch alarms for critical service health, encrypted automated database backups, and vulnerability scanning for container images (including scan-on-push for application images and continuous scanning via Amazon Inspector).

Access controls

Access to Slung systems is granted based on business need and least privilege:

  • Individual user accounts — shared credentials are not used for administrative access
  • Multi-factor authentication for administrative access to cloud management systems
  • Role-based access to production infrastructure via AWS IAM Identity Center and IAM roles
  • Periodic access reviews as part of our compliance program
  • Prompt removal or adjustment of access when personnel leave or change roles

Customer accounts authenticate through Slung's application controls. Production data stores are reachable only from authorized application and worker workloads within our private network controls.

Secure development

We follow secure development and change-management practices, including:

  • Pull-request review before merge to the main branch
  • GitHub branch protection rulesets that require review and block unprotected force-pushes
  • Container-image vulnerability scanning for application images
  • Secrets and credentials kept outside source code
  • Separated testing, staging, and production environments
  • Tracked vulnerability remediation through our security and compliance workflows
  • Change tracking in version control and production deployments via CI/CD (including release-gated production deploys)

Incident response

Slung maintains an incident-response process covering identification, containment, investigation, recovery, customer notification when legally or contractually required, and post-incident review. We document and review this process as part of our security and compliance program, and aim to test it at least annually.

To report a suspected security issue, contact us at contact@slung.com.

Compliance

Slung is implementing a security and compliance program aligned with the SOC 2 Trust Services Criteria and uses Vanta for continuous compliance monitoring. We have not yet completed a SOC 2 examination and do not claim SOC 2 certification.

Related public information is also available in our Privacy Policy and Terms of Service. For security questionnaires or additional documentation, email contact@slung.com.

This page is owned by Slung's security and compliance function, with support from engineering and marketing for accuracy and discoverability. We update it when practices, audits, or policies change. Questions: contact@slung.com.

SlungAI Logo

Subscribe

Subscribe to our newsletter for exclusive updates, insider tips, and offers delivered straight to your inbox.