PRIV-PII-041Subprocessors & PII Handling
Privacy & Data Retention
ExpiredGDPR
A current list of subprocessors is maintained and published. Subprocessors are bound by data protection agreements, and customers are notified of material changes with the opportunity to object.
- Evidence owner
- Helena Brooks
- Privacy
- Last reviewed
- Apr 22, 2025
- Expires
- Apr 22, 2026
SEC-VM-031Patch Management SLA
Vulnerability Management
ExpiredSOC 2
Security patches are prioritized by severity. Critical vulnerabilities are remediated within defined SLA windows, tracked to closure, and reported to security leadership.
- Evidence owner
- Sofia Marchetti
- Security Operations
- Last reviewed
- Mar 30, 2025
- Expires
- Mar 30, 2026
AI-GOV-060AI & Model Governance
AI & Model Governance
Expiring SoonNIST AI RMFISO 27001
AI features operate under a documented governance program covering approved use cases, data handling, human oversight, and evaluation. Customer data is not used to train shared or third-party foundation models without explicit consent.
- Evidence owner
- Helena Brooks
- AI Governance
- Last reviewed
- Sep 30, 2025
- Expires
- Jul 30, 2026
SEC-IR-021Breach Notification Commitments
Incident Response
Expiring SoonGDPRSOC 2
Customers are notified of confirmed breaches affecting their data without undue delay and within the timelines defined in the applicable agreement and regulation. Regulatory notifications follow documented runbooks.
- Evidence owner
- Tomas Reyes
- Security Operations
- Last reviewed
- Jun 20, 2025
- Expires
- Jun 20, 2026
SEC-KMS-004Key Management & Rotation
Encryption & Data Protection
Expiring SoonSOC 2ISO 27001
Encryption keys are managed in a dedicated KMS with hardware-backed protection. Keys are rotated at least annually and on personnel change, with access restricted by least privilege.
- Evidence owner
- Raj Patel
- Platform Security
- Last reviewed
- Jul 15, 2025
- Expires
- Jul 15, 2026
BC-DR-070Business Continuity & Disaster Recovery
Business Continuity & Resilience
CurrentSOC 2ISO 27001
Business continuity and disaster recovery plans define RTO and RPO targets, are tested at least annually, and rely on geographically redundant infrastructure with automated, regularly validated backups.
- Evidence owner
- Tomas Reyes
- Security Operations
- Last reviewed
- Mar 22, 2026
- Expires
- Mar 22, 2027
CLD-INF-050Cloud Hosting & Tenant Segregation
Cloud & Infrastructure Security
CurrentSOC 2ISO 27001
The platform is hosted on a major cloud provider in a logically segregated, multi-tenant architecture. Network controls, security groups, and private subnets isolate production workloads from other environments.
- Evidence owner
- Raj Patel
- Platform Security
- Last reviewed
- Feb 14, 2026
- Expires
- Feb 14, 2027
CMP-CERT-090Compliance Certifications
Compliance & Certifications
CurrentSOC 2ISO 27001CSA CAIQ
The company maintains a SOC 2 Type II report and ISO/IEC 27001 certification. Reports and certificates are available to customers and prospects under NDA through the trust portal.
- Evidence owner
- Sofia Marchetti
- Governance, Risk & Compliance
- Last reviewed
- May 1, 2026
- Expires
- May 1, 2027
PRIV-DR-040Data Retention & Deletion
Privacy & Data Retention
CurrentGDPRISO 27001
Customer data is retained only as long as necessary to provide the service or meet legal obligations. On contract termination, customer data is deleted or returned within the period defined in the data processing agreement.
- Evidence owner
- Helena Brooks
- Privacy
- Last reviewed
- Jan 12, 2026
- Expires
- Jan 12, 2027
SEC-ENC-001Encryption at Rest
Encryption & Data Protection
CurrentSOC 2ISO 27001PCI DSS
All customer data is encrypted at rest using AES-256. Encryption is enabled at the storage layer across all production data stores, including backups and snapshots.
- Evidence owner
- Dana Whitfield
- Security Engineering
- Last reviewed
- Feb 10, 2026
- Expires
- Feb 10, 2027
SEC-ENC-002Encryption in Transit
Encryption & Data Protection
CurrentSOC 2ISO 27001
All data in transit is protected using TLS 1.2 or higher. Legacy protocols (SSL, TLS 1.0/1.1) are disabled, and HSTS is enforced on all public endpoints.
- Evidence owner
- Dana Whitfield
- Security Engineering
- Last reviewed
- Mar 1, 2026
- Expires
- Mar 1, 2027
SEC-IAM-010Access Control & RBAC
Access Control & Identity
CurrentSOC 2ISO 27001NIST CSF
Access to production systems follows role-based access control and least privilege. Access is provisioned through approved requests, reviewed quarterly, and revoked promptly on role change or offboarding.
- Evidence owner
- Mara Lindgren
- Identity & Access
- Last reviewed
- Jan 20, 2026
- Expires
- Jan 20, 2027
SEC-IAM-011MFA & Single Sign-On
Access Control & Identity
CurrentSOC 2NIST CSF
Multi-factor authentication is enforced for all employee and administrative access. Workforce access is federated through SSO with phishing-resistant factors required for privileged roles.
- Evidence owner
- Mara Lindgren
- Identity & Access
- Last reviewed
- Feb 28, 2026
- Expires
- Feb 28, 2027
SEC-IR-020Incident Response Plan
Incident Response
CurrentSOC 2ISO 27001NIST CSF
A documented incident response plan defines roles, severity tiers, and escalation paths. The plan is tested at least annually through tabletop exercises, and post-incident reviews are conducted for all major incidents.
- Evidence owner
- Tomas Reyes
- Security Operations
- Last reviewed
- Apr 5, 2026
- Expires
- Apr 5, 2027
SEC-VM-030Vulnerability Management & Penetration Testing
Vulnerability Management
CurrentSOC 2ISO 27001
Continuous vulnerability scanning runs across production and build pipelines. Independent third-party penetration tests are performed at least annually, and an executive summary is available under NDA.
- Evidence owner
- Sofia Marchetti
- Security Operations
- Last reviewed
- Mar 18, 2026
- Expires
- Mar 18, 2027
VR-TPR-080Vendor & Third-Party Risk Management
Vendor & Third-Party Risk
CurrentSOC 2ISO 27001
Vendors are risk-assessed before onboarding and reassessed periodically based on data sensitivity and criticality. Security and privacy requirements are flowed down through contractual terms.
- Evidence owner
- Mara Lindgren
- Governance, Risk & Compliance
- Last reviewed
- Apr 10, 2026
- Expires
- Apr 10, 2027