Security
Security you can audit, not just trust.
Our security program is aligned to the SOC 2 framework and covers our organization, our cloud infrastructure, access, and vendors. The controls below describe how we protect your data.
Certifications
Independently verified.
SOC 2 Type II
CompleteIndependently audited against the AICPA Trust Services Criteria. Report available under NDA.
ISO 27001
CompleteCertified against the ISO/IEC 27001 information security management standard.
GDPR
CompliantData Processing Addendum available on request. Self-host for data residency.
CCPA / CPRA
CompliantCalifornia residents can request access, deletion, and opt-out at any time.
Organizational security
How we run the program.
Information Security Program
We have an Information Security Program in place that is communicated throughout the organization. It follows the criteria set forth by the SOC 2 Framework, a widely known information security auditing procedure created by the American Institute of Certified Public Accountants.
Third-party audits
Our organization undergoes independent third-party assessments to test our security and compliance controls.
Third-party penetration testing
We perform independent third-party penetration testing at least annually to ensure that the security posture of our services is uncompromised.
Roles and responsibilities
Roles and responsibilities related to our Information Security Program and the protection of our customers' data are well defined and documented. Team members are required to review and accept all of the security policies.
Security awareness training
Our team members are required to complete security awareness training covering industry-standard practices and information security topics such as phishing and password management.
Confidentiality
All team members are required to sign and adhere to an industry-standard confidentiality agreement prior to their first day of work. Because many of our customers operate in security-focused and regulated environments, we take it a step further: confidentiality obligations continue after employment ends, access to customer data is strictly need-to-know, and we are glad to sign customer-specific NDAs on request.
Background checks
We perform background checks on all new team members in accordance with local laws.
Cloud security
Where your data lives, and how it's protected.
Cloud infrastructure security
Our services are hosted with Amazon Web Services (AWS), Google Cloud Platform (GCP), and Convex. They each run robust security programs with multiple certifications.
Data hosting security
Our data is hosted on AWS, GCP, and Convex, located in the United States. See the vendor documentation referenced under Cloud infrastructure security for more information.
Encryption at rest
All databases are encrypted at rest.
Encryption in transit
Our applications encrypt data in transit with TLS/SSL.
Vulnerability scanning
We perform vulnerability scanning and actively monitor for threats.
Logging and monitoring
We log activity across our AWS and GCP cloud infrastructure and monitor it for security and operational issues.
Business continuity and disaster recovery
We use our data hosting provider's backup services to reduce the risk of data loss in the event of a hardware failure, and monitoring services to alert the team to any failures affecting users.
Incident response
We have a process for handling information security events that includes escalation procedures, rapid mitigation, and communication.
Access security
Who can reach what.
Permissions and authentication
Access to cloud infrastructure and other sensitive tools is limited to authorized employees who require it for their role. Where available, we use Single Sign-On (SSO), two-factor authentication (2FA), and strong password policies to protect access to cloud services.
Least privilege access control
We follow the principle of least privilege with respect to identity and access management.
Quarterly access reviews
We perform quarterly access reviews of all team members with access to sensitive systems.
Password requirements
All team members are required to adhere to a minimum set of password requirements and complexity for access.
Password managers
All company-issued laptops use a password manager for team members to manage passwords and maintain complexity.
Vendor and risk management
Managing third parties and risk.
Annual risk assessments
We undergo at least annual risk assessments to identify potential threats, including considerations for fraud.
Vendor risk management
Vendor risk is determined and the appropriate vendor reviews are performed prior to authorizing a new vendor.
Contact us
Questions, or something to report?
If you have any questions, comments, or concerns, or wish to report a potential security issue, please contact us.