Trust Center
Security
Security is set at the holding company and applied across every company we operate. This page describes the controls we run, the frameworks we align to, and where our formal certifications stand today. We do not claim a certification we have not earned.
Key takeaways
- Controls are mapped to the NIST Cybersecurity Framework and the AICPA Trust Services Criteria.
- Data is encrypted in transit and at rest, with role based access and least privilege throughout.
- SOC 2 Type II and ISO 27001 are in progress. We will publish each report and certificate only when it is issued.
- A full security package, including questionnaire responses (SIG, CAIQ) and our subprocessor list, is available to partners under NDA.
Compliance status, stated plainly
We are building toward formal, independent attestation and we are transparent about where we are on that path.
- SOC 2 Type II: in progress. We align our controls to the AICPA Trust Services Criteria today, and we are working toward an independent Type II examination. We will make the report available under NDA once it is issued.
- ISO/IEC 27001: in progress. Our information security management practices are being formalized against the standard.
- NIST Cybersecurity Framework: our security program is organized around the NIST CSF functions of identify, protect, detect, respond, and recover.
- Questionnaires: we complete standardized assessments, including the Shared Assessments SIG and the Cloud Security Alliance CAIQ, on request during vendor review.
We will never represent a certification as complete before it is. If you need independent assurance today, ask us for our current control documentation and we will provide it under NDA.
Encryption
Data in transit is protected with TLS across our web properties and application traffic. Sensitive data at rest is encrypted using strong, industry standard algorithms, including AES 256 for the most sensitive records, with managed key services and documented key handling.
Access control and identity
Access to systems and data follows least privilege. Permissions are role based and reviewed, administrative access is restricted and separated from everyday accounts, and multi factor authentication is available and used for privileged access. Access is provisioned on documented need and removed promptly when it is no longer required.
Monitoring and audit logging
Key systems produce audit trails of security relevant activity. Several of our platforms maintain tamper evident, hash chained audit logs so that a record of who did what, and when, can be verified. Logs are retained to support investigation and review.
Secure development
We build and maintain our own software. Changes move through review before release, dependencies are watched for known vulnerabilities, and security considerations are part of design rather than an afterthought. Because we own the stack, we control the pace at which issues are fixed.
Malware and content scanning
Inbound mail and uploaded files across our platforms are scanned for malware before they are processed or stored, and unsafe content is rejected.
Vendors and subprocessors
We rely on a small set of established infrastructure providers, including major cloud platforms such as Amazon Web Services, and we hold our subprocessors to security expectations consistent with our own. A current subprocessor list is available on request, and we commit to reasonable advance notice, typically at least thirty days, before adding a subprocessor that handles customer data.
Resilience and backups
Production data is backed up, and backups are used to support recovery. Business continuity and recovery practices are documented and improved as our platforms grow.
Incident response
We maintain an incident response process for identifying, containing, and remediating security events, and for notifying affected customers without undue delay in line with our contractual and legal obligations. Suspected vulnerabilities can be reported to us directly through our vulnerability disclosure policy.
Personnel
Our teams are small and long tenured. People are granted access based on role, are expected to follow our security and confidentiality standards, and receive guidance appropriate to their responsibilities.
Questions and Answers
Questions from reviewers
Do you have a SOC 2 report or ISO 27001 certificate we can review?
Can you complete our security questionnaire (SIG, CAIQ, or a custom form)?
Will you sign a Data Processing Addendum?
How do we report a security vulnerability?
Vendor review
Need documentation for a review?
Security package, Data Processing Addendum, subprocessor list, accessibility VPAT, certificate of insurance, or a completed questionnaire. Tell us what your team needs.
