Sacramento, California Mon to Fri, 9:00 AM to 6:00 PM Pacific
DotNet Holdings

Trust Center

Security

Security is set at the holding company and applied across every company we operate. This page describes the controls we run, the frameworks we align to, and where our formal certifications stand today. We do not claim a certification we have not earned.

Key takeaways

  • Controls are mapped to the NIST Cybersecurity Framework and the AICPA Trust Services Criteria.
  • Data is encrypted in transit and at rest, with role based access and least privilege throughout.
  • SOC 2 Type II and ISO 27001 are in progress. We will publish each report and certificate only when it is issued.
  • A full security package, including questionnaire responses (SIG, CAIQ) and our subprocessor list, is available to partners under NDA.

Compliance status, stated plainly

We are building toward formal, independent attestation and we are transparent about where we are on that path.

  • SOC 2 Type II: in progress. We align our controls to the AICPA Trust Services Criteria today, and we are working toward an independent Type II examination. We will make the report available under NDA once it is issued.
  • ISO/IEC 27001: in progress. Our information security management practices are being formalized against the standard.
  • NIST Cybersecurity Framework: our security program is organized around the NIST CSF functions of identify, protect, detect, respond, and recover.
  • Questionnaires: we complete standardized assessments, including the Shared Assessments SIG and the Cloud Security Alliance CAIQ, on request during vendor review.

We will never represent a certification as complete before it is. If you need independent assurance today, ask us for our current control documentation and we will provide it under NDA.

Encryption

Data in transit is protected with TLS across our web properties and application traffic. Sensitive data at rest is encrypted using strong, industry standard algorithms, including AES 256 for the most sensitive records, with managed key services and documented key handling.

Access control and identity

Access to systems and data follows least privilege. Permissions are role based and reviewed, administrative access is restricted and separated from everyday accounts, and multi factor authentication is available and used for privileged access. Access is provisioned on documented need and removed promptly when it is no longer required.

Monitoring and audit logging

Key systems produce audit trails of security relevant activity. Several of our platforms maintain tamper evident, hash chained audit logs so that a record of who did what, and when, can be verified. Logs are retained to support investigation and review.

Secure development

We build and maintain our own software. Changes move through review before release, dependencies are watched for known vulnerabilities, and security considerations are part of design rather than an afterthought. Because we own the stack, we control the pace at which issues are fixed.

Malware and content scanning

Inbound mail and uploaded files across our platforms are scanned for malware before they are processed or stored, and unsafe content is rejected.

Vendors and subprocessors

We rely on a small set of established infrastructure providers, including major cloud platforms such as Amazon Web Services, and we hold our subprocessors to security expectations consistent with our own. A current subprocessor list is available on request, and we commit to reasonable advance notice, typically at least thirty days, before adding a subprocessor that handles customer data.

Resilience and backups

Production data is backed up, and backups are used to support recovery. Business continuity and recovery practices are documented and improved as our platforms grow.

Incident response

We maintain an incident response process for identifying, containing, and remediating security events, and for notifying affected customers without undue delay in line with our contractual and legal obligations. Suspected vulnerabilities can be reported to us directly through our vulnerability disclosure policy.

Personnel

Our teams are small and long tenured. People are granted access based on role, are expected to follow our security and confidentiality standards, and receive guidance appropriate to their responsibilities.

Questions and Answers

Questions from reviewers

Do you have a SOC 2 report or ISO 27001 certificate we can review?
Both are in progress. We do not yet hold a completed SOC 2 Type II report or an ISO 27001 certificate, and we will not claim one until it is issued. In the meantime we provide detailed control documentation and completed security questionnaires under NDA. Contact us to request the current package.
Can you complete our security questionnaire (SIG, CAIQ, or a custom form)?
Yes. We routinely complete the Shared Assessments SIG, the Cloud Security Alliance CAIQ, and buyer specific questionnaires as part of vendor review. Send us your questionnaire and your timeline.
Will you sign a Data Processing Addendum?
Yes. A Data Processing Addendum is available to customers on request. See our data protection page for the commitments it reflects.
How do we report a security vulnerability?
Email security@dotnetholdings.com or follow our vulnerability disclosure policy. We welcome good faith research and will work with you on remediation.

Vendor review

Need documentation for a review?

Security package, Data Processing Addendum, subprocessor list, accessibility VPAT, certificate of insurance, or a completed questionnaire. Tell us what your team needs.