Skip to content

New: the 2026 Operating Letter is live Read it →

BLUEPRINT

Security & Trust.

enterprise-grade infrastructure under every engagement.

Certifications

  • SOC 2 Type II

    current

    annual audit · most recent: Q1 2026

  • GDPR · CCPA

    current

    DPA available · EU sub-processors disclosed

  • PCI DSS · SAQ A

    current

    payment processing partners only

  • HIPAA

    available

    BAA available on enterprise tier

  • ISO 27001

    in progress

    in progress · target Q4 2026

Controls

  • Access

    SSO + MFA required for all users. Role-based access control. Quarterly access review.

  • Encryption

    TLS 1.3 in transit. AES-256 at rest. Customer-controlled keys available on enterprise tier.

  • Data residency

    US-East, US-West, EU-West regions. Data residency contractually guaranteed.

  • Backup + DR

    Hourly snapshots. Point-in-time restore. 24-hour RTO, 1-hour RPO.

  • Pen-testing

    Annual third-party penetration test. Reports available under NDA.

  • Sub-processors

    Disclosed at /legal/sub-processors. 30-day change notification.

Security inquiries

security@theblueprintcompany.org

View system status →