Security

Enterprise-grade security for your compliance data

Your compliance data is sensitive. We protect it with SOC 2 Type II certified infrastructure, AES-256 encryption, and the same security controls we help you implement. Security is not just our product. It is how we operate.

256-bitAES encryption
99.9%Uptime SLA
SOC 2Type II certified
24/7Security monitoring

01Certifications

Held to the standards we help you meet.

  • Certified

    SOC 2 Type II

    Audited annually by independent third-party auditors. Report available under NDA.

  • Aligned

    ISO 27001 Aligned

    Security controls aligned with ISO 27001 information security management standards.

  • Compliant

    GDPR Compliant

    Full GDPR compliance with DPA available. EU data subjects have full rights enforcement.

  • BAA Available

    HIPAA Ready

    Business Associate Agreement available for healthcare organizations handling PHI.

02Infrastructure

How we protect your data.

  • 01

    Encryption Everywhere

    All data encrypted at rest with AES-256 and in transit with TLS 1.3. Database encryption uses AWS KMS with customer-managed keys available on Enterprise plans.

  • 02

    AWS Infrastructure

    Hosted on AWS with SOC 2, ISO 27001, and FedRAMP certified infrastructure. All data stored in US data centers (us-east-1) with cross-region backups.

  • 03

    Zero-Trust Access

    Role-based access control, SSO integration with SAML 2.0 and OIDC, mandatory MFA for all team members, and IP allowlisting on Enterprise plans.

  • 04

    24/7 Security Monitoring

    Real-time threat detection, automated vulnerability scanning, and intrusion detection. Security events logged and monitored continuously.

  • 05

    Automated Backups

    Continuous database backups with point-in-time recovery. Daily encrypted snapshots retained for 30 days. Cross-region replication for disaster recovery.

  • 06

    Complete Audit Trail

    Every action logged with immutable audit trails. User activity, API calls, evidence changes, and administrative actions all tracked for compliance.

03Data protection

Your compliance data belongs to you.

We follow data protection principles aligned with GDPR, CCPA and industry practice.

  • Data minimization

    We collect only data necessary for the service. No tracking, no selling, no third-party advertising.

  • Purpose limitation

    Your data is used only for providing compliance automation. Never shared without explicit consent.

  • Data retention

    You control retention periods. Upon account termination, all data permanently deleted within 30 days.

  • Right to export

    Export all your data at any time in standard formats. Your compliance evidence belongs to you.

  • Subprocessor transparency

    Complete list of subprocessors available. You are notified of any changes before they take effect.

  • Breach notification

    In the unlikely event of a security incident, affected customers notified within 72 hours per GDPR requirements.

04Integration security

How we connect to your tools.

Evidence collection needs read access to your infrastructure. These are the limits on it.

  • Read-only access

    All integrations operate on read-only basis. We never write to or modify your production systems.

  • Official APIs only

    We use only official vendor APIs. No screen scraping, no stored credentials, no direct database access.

  • OAuth 2.0

    Industry-standard OAuth 2.0 for all integrations. Tokens encrypted and can be revoked at any time.

  • Minimal scopes

    We request only the minimum API scopes needed. No access to data beyond what is required for evidence collection.

Security documentation

Request our SOC 2 Type II report, penetration test results, security questionnaire responses or custom documentation.

Report a vulnerability

We welcome responsible disclosure from security researchers and respond within 24 hours.

Enterprise security

SSO, SCIM provisioning, custom data residency or dedicated infrastructure: talk to the enterprise team.

05Questions

Security questions.

Have security questions?

Our security team can answer questions, provide documentation or schedule a security review call with your team.