Sacramento, California Mon to Fri, 9:00 AM to 6:00 PM Pacific
DotNet Holdings

Trust Center

Trust Center

The information a serious partner needs to evaluate us: how we protect data, how we govern the companies we operate, the standards we hold, and the documentation we make available under review. Everything here is current, and we state what we do not yet have as plainly as what we do.

Legal entityDotNet Holdings LLCPrivately held holding company
HeadquartersSacramento, CaliforniaUnited States
Security programAligned to NIST CSFAICPA Trust Services Criteria
InsuranceGL, E and O, CyberCertificates provided at onboarding

What you can review

Everything a due diligence team looks for

Security, privacy, accessibility, ethics, and governance, each documented and kept current. We state what we do not yet hold as plainly as what we do.

Standards and status

Honest about where we are

Our security program is organized around the NIST Cybersecurity Framework and mapped to the AICPA Trust Services Criteria. SOC 2 Type II and ISO 27001 are in progress. We do not yet hold a completed report or certificate, and we will not claim one until it is issued.

In the meantime, we provide detailed control documentation and completed security questionnaires, including the SIG and CAIQ, to prospective partners under NDA. We carry commercial general liability, professional liability, and cyber insurance, and we provide certificates during onboarding.

Read the security page
SOC 2 Type IIIn progress
ISO/IEC 27001In progress
FrameworkNIST CSF, AICPA TSC
QuestionnairesSIG, CAIQ on request
Data Processing AddendumAvailable on request
AccessibilityWCAG 2.2 AA target

Documentation

Request the documents your review needs

Security package, DPA, subprocessor list, accessibility VPAT, certificate of insurance, or a completed questionnaire. We respond within one business day.

We reply within one business day. Your details reach our team directly and are never shared or sold.