Security
Application security
Authentication
Secure Access
API
Roles & permissions
Our best practice security approach
SOC 2
Bunny is SOC 2 TYPE II certified. This certification provides assurance that we are operating at a level that is in compliance or better than the standards outlined by the American Institute of Certified Public Accountants (AICPA).
Payments
We process all payments through PCI compliant payment gateway partners such as Stripe. Bunny does not store credit card details or card holder information.
Infrastructure
Bunny operates servers hosted on Amazon Web Services (AWS). Access to AWS is heavily restricted.
Incident management
Bunny operates several systems to monitor the health of our service and detect incidents. If a security incident occurs Bunny will notify all affected customers with undue delay.
Responsible disclosure
Please report any vulnerabilities to security@bunny.com. We will immediately assign a ticket id number for each report and a member of our engineering team will reply back within 1 business day.