Security
Tediware handles sensitive EDI data for businesses of all sizes. We take a defense-in-depth approach to security, with multiple layers of protection across infrastructure, application, and data.
Infrastructure
Tediware runs entirely on AWS in the ca-central-1 (Canada) region. Our infrastructure includes:
- Private subnets for worker instances with no direct internet access
- Security groups restricting traffic between tiers (load balancer, web, worker, database)
- VPC flow logs monitoring rejected traffic
- AWS WAF in front of the application load balancer, blocking known malicious IP ranges, exploit signatures, and per-IP request floods
- Administrative access runs over a private WireGuard-based mesh VPN; no SSH is exposed to the internet
- NAT Gateways providing fixed outbound IPs for partner whitelisting
Encryption
All data is encrypted both in transit and at rest:
- HTTPS enforced on all connections via HSTS and application-level SSL enforcement, with TLS 1.3 negotiated where supported and TLS 1.2 as the minimum
- Database encryption enabled on our managed PostgreSQL instance (RDS)
- Sensitive fields (credentials, private keys, processing results) encrypted at the application level
- Processing results are compressed and encrypted before storage
Organization Isolation
Tediware is a multi-tenant platform. Every database query is scoped to the authenticated organization, and an organization assignment is immutable once made, so a record cannot be moved between organizations or re-pointed at another one. Scoping is applied at every access point and checked in code review on every change.
Authentication
User passwords are hashed with bcrypt. Sessions are database-backed with HttpOnly, SameSite cookies, enabling immediate invalidation. API access uses cryptographically generated keys scoped to individual organizations.
- Two-factor authentication (TOTP) with recovery codes, which an organization can require of every member
- A 12-character minimum, screened against known-breached password corpora, following NIST SP 800-63B
- A per-account cooldown after five failed sign-in attempts, which lifts on its own
- A 30-day absolute session lifetime, so every user signs in again at least monthly, and satisfies any second factor again with it
- Changing a password signs out every other session, so a reset ends any access an attacker already had
AS2 File Transfer
For trading partners using the AS2 protocol, file transfers are handled through AWS Transfer Family with application-layer encryption and signing via CMS (Cryptographic Message Syntax). Each organization gets isolated AWS resources (profiles, agreements, connectors) with dedicated S3 paths. MDN receipts provide non-repudiation for every transmission.
Application Security
- CSRF protection on all browser-based requests
- Rate limiting on authentication endpoints, public APIs, and cost-sensitive operations
- Parameterized queries throughout to prevent SQL injection
- Strong parameter whitelisting on all API endpoints
- Static security analysis (Brakeman) as part of our development workflow
- Sensitive parameters (passwords, tokens, keys) are filtered from all logs
- Automated dependency scanning (Dependabot) across our Ruby and JavaScript dependencies, with an audit of the JavaScript dependencies that runs before every push and blocks it while a high-risk advisory is outstanding
Webhook Security
Outbound webhooks are signed with HMAC-SHA256 and include timestamps for replay protection. Inbound webhooks from third parties (such as payment processors) are verified via signature validation with idempotency checks to prevent duplicate processing.
AI Feature Security
Tediware includes AI-powered assistants for mapping and diagnostics. These features operate under strict controls: only server-side-allowlisted models and completion types are accepted, all data access is scoped to the authenticated organization, and assistant prompts include explicit domain restrictions to prevent misuse.
Monitoring
We monitor infrastructure health with CloudWatch alarms covering CPU, memory, disk, database connections, HTTP error rates, and response times. Alarms trigger 24/7 on-call paging through a dedicated incident alerting service, with escalation if a page goes unacknowledged. AWS GuardDuty continuously analyzes network traffic, DNS activity, and control-plane events for threats across our AWS accounts. Container logs are rotated and capped to prevent unbounded growth, and ALB access logs are retained for audit purposes.
Database
Our production database runs on managed PostgreSQL (RDS) with Multi-AZ deployment for high availability, automated backups with 7-day retention, deletion protection enabled, encryption at rest, and no public accessibility. The database is only reachable from application instances within the VPC.
Object Storage
Files stored in S3 are not publicly accessible and cannot be enumerated without credentials. Access is enforced at the application and IAM policy level, with versioning enabled on production buckets.
Questions
If you have questions about our security practices, please contact us at info@tediware.com .