Compliance & Trust
Enterprise-Grade Compliance
We maintain the highest standards of security and compliance to protect your data and meet regulatory requirements.
01
Certifications & Standards
We're working toward major security standards and regulations — here's where each one currently stands
SOC 2 Type II · In Progress
Controls aligned to SOC 2 criteria; independent certification in progress
GDPR · Aligned
Data practices aligned with the EU General Data Protection Regulation
CCPA · Aligned
Data practices aligned with the California Consumer Privacy Act
ISO 27001 · In Progress
International standard for information security management
HIPAA · Available
Healthcare data controls available for enterprise customers
FERPA · Aligned
Data practices aligned with the Family Educational Rights and Privacy Act
02
Our Security Practices
How we protect your data every day
Data Encryption
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Encryption keys are managed using industry-standard key management services.
Access Control
Role-based access control with principle of least privilege. Multi-factor authentication required for all internal systems.
Data Retention
Clear data retention policies with automatic purging. Users can request data deletion at any time.
Vendor Management
All third-party vendors undergo security assessments. We maintain a limited number of sub-processors.
Incident Response
24/7 security monitoring with documented incident response procedures. Customers notified within 72 hours of any breach.
Employee Training
All employees complete annual security awareness training. Background checks required for all staff with data access.
03
Sub-Processors
Third-party services that process data on our behalf
Data Processing Agreement
Enterprise customers can request our standard Data Processing Agreement (DPA) for GDPR and other regulatory compliance.
Our security and compliance team is available to answer your questions and provide documentation. [email protected]