Enterprise Security, Compliance & SLA Transparency
Self-serve access to our SOC 2 Type II audit, ISO 27001 certification, penetration test attestations, and vendor security questionnaires (CAIQ / SIG Lite).
SOC 2 Type II Annual Audit Report (Executive Summary & Bridge Letter)
AICPA SOC 2 Type II independent auditor certification covering Security, Availability, and Confidentiality trust principles.
ISO/IEC 27001:2022 Information Security Management Certificate
International standard specification for Information Security Management Systems (ISMS).
Cloud Security Alliance (CSA) CAIQ v4 Pre-Filled Assessment
Consensus Assessments Initiative Questionnaire covering 261 cloud security controls across 17 domains.
Shared Assessments Standard Information Gathering (SIG Lite 2026)
Standardized vendor risk evaluation spreadsheet favored by Fortune 500 financial institutions.
GDPR Data Processing Addendum (DPA) with Standard Contractual Clauses (SCCs)
Article 28 GDPR compliant data processing agreement for EU enterprise customers.
Annual Third-Party Network & Application Penetration Test Attestation
Grey-box web application and cloud sandbox breakout penetration test conducted by Bishop Fox.
Authorized Cloud Subprocessors
All customer sandbox workloads and data persist exclusively in certified enterprise data centers.
| Subprocessor | Function & Scope | Data Region | Compliance Standards |
|---|---|---|---|
| Google Cloud Platform (GCP) | Core Infrastructure & Kubernetes Fleet | us-central1 (Council Bluffs, IA, USA) | SOC 1/2/3, ISO 27001, HIPAA, FedRAMP High |
| Neon / PostgreSQL | Relational Database Cluster & WAL Replicas | AWS us-east-1 (N. Virginia, USA) | SOC 2 Type II, ISO 27001, GDPR |
| Redis Enterprise Cloud | In-Memory Session State & Rate Limiting | GCP us-central1 | SOC 2 Type II, PCI-DSS Level 1 |
| Cloudflare Inc. | Edge CDN, WAF & Anti-DDoS Gateway | Global Edge (300+ Cities) | SOC 2 Type II, ISO 27001, PCI-DSS |
Need Custom Security Review or Custom DPA?
Our Chief Information Security Officer (CISO) and legal team routinely execute enterprise Master Services Agreements (MSAs), custom DPAs, and bespoke security questionnaires for Fortune 500 teams.