ALL SYSTEMS OPERATIONAL

Trust, continuously earned.

Independent attestations, transparent practices, and real-time status — everything your security and procurement teams need to say yes.

CERTIFICATIONS & ATTESTATIONS
SOC 2
Type II
ISO 27001
Certified
FedRAMP High
In process
DoD IL5
In process
HIPAA
Aligned
GDPR
Compliant
PCI DSS
Level 1
CSA STAR
Level 2
SECURITY PRACTICES

How we protect your data.

Encryption everywhere

AES-256 at rest, TLS 1.3 in transit, customer-managed keys available.

Data residency

US, EU, and sovereign regions — your data stays where you require.

Least-privilege access

SSO, SCIM, granular RBAC, and full access logging by default.

Continuous monitoring

We run threatDefendr on threatDefendr — assessed every single day.

Vulnerability management

Continuous scanning, third-party pen tests, and a public bug bounty.

Subprocessors

A current, public list with advance notice of any change.

ALL SYSTEMS OPERATIONAL

Trust, continuously earned.

Independent attestations, transparent practices, and real-time status — everything your security and procurement teams need to say yes.

// CERTIFICATIONS & ATTESTATIONS
SOC 2
Type II
ISO 27001
Certified
FedRAMP High
In process
DoD IL5
In process
HIPAA
Aligned
GDPR
Compliant
PCI DSS
Level 1
CSA STAR
Level 2
// SECURITY PRACTICES

How we protect your data.

Encryption everywhere

AES-256 at rest, TLS 1.3 in transit, customer-managed keys available.

Data residency

US, EU, and sovereign regions — your data stays where you require.

Least-privilege access

SSO, SCIM, granular RBAC, and full access logging by default.

Continuous monitoring

We run threatDefendr on threatDefendr — assessed every single day.

Vulnerability management

Continuous scanning, third-party pen tests, and a public bug bounty.

Subprocessors

A current, public list with advance notice of any change.