Last updated July 20, 2026

Compliance program

Transparent status for security and compliance initiatives.

We believe transparency builds trust. Our compliance roadmap shows which controls are implemented today, which are in progress, and which are planned. We do not claim certifications we have not achieved.

Compliance roadmap

HTTPS

All web and API traffic is served over HTTPS with modern TLS configurations.

Security

Implemented

HTTPS / TLS

All customer traffic is encrypted in transit using modern TLS.

Security

Implemented

TLS Encryption

Data in transit is protected using TLS 1.2+ across customer-facing endpoints.

Data Protection

Implemented

Encryption in transit

API and application communications use encrypted channels.

Data Protection

Implemented

Authentication

Industry-standard authentication controls protect platform access.

Security

Implemented

Secure authentication

Industry-standard authentication for platform access.

Security

Implemented

Cloud Infrastructure

Production workloads run on enterprise cloud infrastructure with operational controls.

Infrastructure

Implemented

Role-based access control

Granular permissions for teams, territories, and admin functions.

Security

Implemented

Secure Development Practices

Security is integrated into design, development, testing, and release workflows.

Development

Implemented

Cloud hosting

Production workloads run on enterprise cloud infrastructure.

Infrastructure

Implemented

Backup Strategy

Automated backups with documented restore procedures for critical systems.

Infrastructure

Implemented

Regular backups

Automated backups with tested restore procedures.

Infrastructure

Implemented

Security Documentation

Formalizing security policies, standards, and operational runbooks for the Trust Center.

Compliance

In Progress

Secure software development

Security practices integrated into design, development, and release.

Development

Implemented

Internal Security Reviews

Periodic internal reviews of access, configuration, and control effectiveness.

Compliance

In Progress

Monitoring & alerting

Operational monitoring for availability and security events.

Operations

Implemented

Annual Penetration Testing

Independent third-party penetration testing program.

Security

Planned

Vulnerability scanning

Ongoing scanning of dependencies and infrastructure.

Security

In Progress

ISO 27001 Alignment

Controls aligned to ISO 27001 framework, not certified.

Compliance

Planned

Annual penetration testing

Independent third-party penetration testing program.

Security

Planned

SOC 2 Readiness

SOC 2 readiness program, not certified.

Compliance

Planned

ISO 27001 alignment

Controls aligned to ISO 27001 framework — not certified.

Compliance

Planned

SOC 2 readiness

SOC 2 readiness program — not certified.

Compliance

Planned