Security & Trust.
enterprise-grade infrastructure under every engagement.
Certifications
-
SOC 2 Type II
currentannual audit · most recent: Q1 2026
-
GDPR · CCPA
currentDPA available · EU sub-processors disclosed
-
PCI DSS · SAQ A
currentpayment processing partners only
-
HIPAA
availableBAA available on enterprise tier
-
ISO 27001
in progressin progress · target Q4 2026
Controls
-
Access
SSO + MFA required for all users. Role-based access control. Quarterly access review.
-
Encryption
TLS 1.3 in transit. AES-256 at rest. Customer-controlled keys available on enterprise tier.
-
Data residency
US-East, US-West, EU-West regions. Data residency contractually guaranteed.
-
Backup + DR
Hourly snapshots. Point-in-time restore. 24-hour RTO, 1-hour RPO.
-
Pen-testing
Annual third-party penetration test. Reports available under NDA.
-
Sub-processors
Disclosed at /legal/sub-processors. 30-day change notification.