Encryption at rest & in transit
AES-256-GCM at rest, TLS 1.3 in transit, key rotation every 90 days.
Live
Access reviews
Quarterly review of every employee with production access.
Live
Incident response runbook
Severity definitions, named oncalls, customer-facing disclosure template.
Live
Pen test · external
Annual, report summary published.
Q2 2026
SOC 2 Type I
AICPA TSC: Security, Availability, Confidentiality.
Q3 2026
SOC 2 Type II
Report covering 12-month window.
Q3 2027
State-level residency partitioning
Honors state privacy laws that require in-state storage.
Q4 2026
Customer-signed transparency report
Subpoenas, takedowns, government requests, published quarterly.
Q1 2027