Security
Enterprise-grade security for your compliance data
Your compliance data is sensitive. We protect it with SOC 2 Type II certified infrastructure, AES-256 encryption, and the same security controls we help you implement. Security is not just our product. It is how we operate.
01Certifications
Held to the standards we help you meet.
- Certified
SOC 2 Type II
Audited annually by independent third-party auditors. Report available under NDA.
- Aligned
ISO 27001 Aligned
Security controls aligned with ISO 27001 information security management standards.
- Compliant
GDPR Compliant
Full GDPR compliance with DPA available. EU data subjects have full rights enforcement.
- BAA Available
HIPAA Ready
Business Associate Agreement available for healthcare organizations handling PHI.
02Infrastructure
How we protect your data.
- 01
Encryption Everywhere
All data encrypted at rest with AES-256 and in transit with TLS 1.3. Database encryption uses AWS KMS with customer-managed keys available on Enterprise plans.
- 02
AWS Infrastructure
Hosted on AWS with SOC 2, ISO 27001, and FedRAMP certified infrastructure. All data stored in US data centers (us-east-1) with cross-region backups.
- 03
Zero-Trust Access
Role-based access control, SSO integration with SAML 2.0 and OIDC, mandatory MFA for all team members, and IP allowlisting on Enterprise plans.
- 04
24/7 Security Monitoring
Real-time threat detection, automated vulnerability scanning, and intrusion detection. Security events logged and monitored continuously.
- 05
Automated Backups
Continuous database backups with point-in-time recovery. Daily encrypted snapshots retained for 30 days. Cross-region replication for disaster recovery.
- 06
Complete Audit Trail
Every action logged with immutable audit trails. User activity, API calls, evidence changes, and administrative actions all tracked for compliance.
03Data protection
Your compliance data belongs to you.
We follow data protection principles aligned with GDPR, CCPA and industry practice.
Data minimization
We collect only data necessary for the service. No tracking, no selling, no third-party advertising.
Purpose limitation
Your data is used only for providing compliance automation. Never shared without explicit consent.
Data retention
You control retention periods. Upon account termination, all data permanently deleted within 30 days.
Right to export
Export all your data at any time in standard formats. Your compliance evidence belongs to you.
Subprocessor transparency
Complete list of subprocessors available. You are notified of any changes before they take effect.
Breach notification
In the unlikely event of a security incident, affected customers notified within 72 hours per GDPR requirements.
04Integration security
How we connect to your tools.
Evidence collection needs read access to your infrastructure. These are the limits on it.
Read-only access
All integrations operate on read-only basis. We never write to or modify your production systems.
Official APIs only
We use only official vendor APIs. No screen scraping, no stored credentials, no direct database access.
OAuth 2.0
Industry-standard OAuth 2.0 for all integrations. Tokens encrypted and can be revoked at any time.
Minimal scopes
We request only the minimum API scopes needed. No access to data beyond what is required for evidence collection.
Security documentation
Request our SOC 2 Type II report, penetration test results, security questionnaire responses or custom documentation.
Report a vulnerability
We welcome responsible disclosure from security researchers and respond within 24 hours.
Enterprise security
SSO, SCIM provisioning, custom data residency or dedicated infrastructure: talk to the enterprise team.
05Questions
Security questions.
Have security questions?
Our security team can answer questions, provide documentation or schedule a security review call with your team.