Trust & Security
We earn the trust of our customers and partners through transparency, security, and compliance - backed by infrastructure built to the highest standards in identity security.
- SOC 2
- CSA STAR
- CISA
- GDPR
- CCPA
Frameworks & Certifications
Independent attestationsand the frameworks we align to.
Third-party audits, regulatory alignment, and cross-border privacy, renewed on a schedule and available to security reviewers on request.
- SOC 2
SOC 2 Type II
Annually audited. Controls span security, availability, and confidentiality.
- CSA STAR
CSA STAR Level 1
Cloud Security Alliance Level 1 compliant.
- CISA
CISA Secure-by-Design Pledge
Prioritizing the security of customers.
- GDPR
GDPR
Compliant data processing with EU data residency options.
- CCPA
CCPA
California Consumer Privacy Act compliant.
- ReviewersRequest our reports & DPIA package.Contact security
The Program
37 controls, six domains,one continuous program.
The Full Program
Every control we run,documented in plain language.
6 domains · 37 controls
Information Security Management
Our CISO owns the information security program, supported by a Security Steering Committee and quarterly Board oversight.
Our CISO owns the information security program, supported by a Security Steering Committee and quarterly Board oversight.
We maintain a comprehensive policy set, approved by management, reviewed at least annually, and available to all employees on our internal portal.
All candidates undergo screening and reference checks as part of the hiring process, in accordance with local laws.
All new hires sign an employment agreement covering confidentiality, code of conduct, and intellectual property.
All employees complete security awareness training within 30 days of joining and annually thereafter, with additional role-specific training for higher-risk roles.
We run a formal risk management program, led by the CISO, with an annual risk assessment and management-approved remediation.
A documented disciplinary process addresses violations of our security policies.
We undergo an independent annual SOC 2 Type II examination by a qualified third-party CPA firm.
We maintain a cyber insurance policy with coverage appropriate to the scale and risk profile of our business.
Network & Infrastructure Security
Our cloud infrastructure runs across multiple availability zones and auto-scales to maintain availability under demand.
Our cloud infrastructure runs across multiple availability zones and auto-scales to maintain availability under demand.
All production activity is logged, centralized, and continuously monitored, with alerts triggered on anomalies.
Infrastructure and data are distributed across multiple availability zones with automated backups, and recovery is tested through an annual DR drill.
Access is provisioned by role and baselined regularly, with permissions to production, databases, and applications reviewed at least annually.
The production environment is fully separated from the corporate environment, requiring two-factor authentication and IP filtering for access.
Resources are protected by firewalls, VPNs, encrypted tunnels, intrusion-detection monitoring, and least-privilege port configuration.
We review our cloud provider's SOC 2 report annually and document the complementary controls we operate.
Data Privacy & Protection
All data at rest is encrypted with AES-256 using hardware-bound keys, with no action required from customers.
All data at rest is encrypted with AES-256 using hardware-bound keys, with no action required from customers.
All traffic is served over HTTPS and encrypted in transit using TLS 1.2+ with strong cipher suites.
Data retention and deletion follow customer contracts and applicable law, with customer data returned on termination and then securely erased.
Encryption keys are hardware-bound with unique keys per environment, automated rotation, dual authorization, and full lifecycle logging.
We classify data by sensitivity and maintain an inventory of sensitive and personal data, including owner, location, and processing purpose.
We apply data minimization and privacy impact assessments, maintain a disclosed sub-processor list, and notify the data controller of a personal data breach within 72 hours.
Incident Detection & Response
Every pull request undergoes mandatory peer review, documented in our source-control tool, before it can be merged.
Every pull request undergoes mandatory peer review, documented in our source-control tool, before it can be merged.
We maintain a tested incident response plan with defined escalation, rapid mitigation, and post-incident root-cause analysis.
Our Security team monitors production continuously, with a defined escalation matrix and time-bound response targets for critical alerts.
We formally assess vendors and sub-processors at least annually, with a higher bar for those handling sensitive data or critical systems.
Breach notification procedures meet GDPR and customer-contractual SLAs and are documented in our Incident Response Policy and DPAs.
Product Security
Independent third-party experts perform a detailed penetration test of the application and infrastructure at least annually, with critical and high findings resolved.
Independent third-party experts perform a detailed penetration test of the application and infrastructure at least annually, with critical and high findings resolved.
The platform supports SAML 2.0, OpenID Connect, OAuth 2.0, and LDAP/Active Directory, plus FIDO2 passkeys, hardware tokens, push, and one-time passwords.
MFA is required for access to sensitive systems and for privileged access to sensitive data.
We follow a documented SDLC with OWASP secure coding standards, mandatory code review, automated testing, and SAST and dependency scanning as CI gates.
Vulnerabilities are scanned continuously, prioritized using CVSS, and remediated against defined SLAs.
All production changes follow a documented change-control process with approval, testing, and a required rollback plan.
Endpoint Security
All corporate devices use full-disk AES-256 encryption enforced via MDM and can be remotely wiped if lost or compromised.
All corporate devices use full-disk AES-256 encryption enforced via MDM and can be remotely wiped if lost or compromised.
Employee devices are enrolled in MDM with enforced patching, screen lock, and managed configuration.
Endpoint detection and response and antivirus run on all endpoints via a centralized tool with automatically updated signatures.
Remote-work and BYOD protections are governed by our Acceptable Use, BYOD, and Physical Security policies.