Security & Compliance You Can Verify
We hold ourselves to the highest security standards. Explore our compliance framework alignment, download security documentation, and review our security practices.
Security & Compliance Program
Our security practices are designed to align with industry frameworks and backed by automated evidence collection from integrated systems.
Framework Alignment
Our controls are designed to align with SOC 2, ISO 27001, HIPAA, and GDPR. SOC 2 coverage is inherited via our infrastructure provider (Base44) — not independently certified by Grant Search US.
Automated Evidence
Evidence pulled directly from AWS Config, GitHub Audit Log, Okta, and Datadog — machine-collected, not manually entered.
Chain of Custody
Every evidence artifact is traceable to its source system, collection timestamp, and verifier — full audit trail.
Continuous Monitoring
Real-time control drift detection with automated alerts — not point-in-time snapshots. Issues are caught and remediated continuously.
Compliance Frameworks We Align With
Our practices are designed to meet these industry standards
SOC 2 Type II
Inherited via infrastructure provider (Base44)
AlignedISO 27001
Controls designed to align with ISO 27001
AlignedHIPAA
Compatible data handling for healthcare users
AlignedGDPR
Privacy controls aligned with GDPR requirements
AlignedSecurity Reports & Documents
Download our compliance documentation. Some reports require an NDA.
Security Whitepaper
Comprehensive overview of our security architecture, controls, and practices.
Penetration Test Report (2026)
Annual penetration test results by Bishop Fox. All critical findings remediated.
Data Processing Agreement (DPA)
Standard DPA template for GDPR compliance. Available for immediate download.
Incident Response Plan Summary
Overview of our incident response procedures and communication protocols.
Security Practices
How we protect your data
Encryption at Rest
AES-256 encryption for all stored data including databases, backups, and file storage.
Encryption in Transit
TLS 1.2+ for all network traffic. HSTS enabled. Perfect forward secrecy.
Access Controls
Role-based access control (RBAC) with least-privilege. SSO + MFA enforced for all internal users.
Vulnerability Management
Continuous vulnerability scanning. 30-day SLA for critical patch remediation.
Incident Response
24/7 monitoring with < 4 hour critical incident response time. Documented IR playbook.
Data Retention
Configurable retention policies. Secure deletion on request per GDPR/CCPA.
Subprocessor List
Third-party services with access to customer data
| Provider | Purpose |
|---|---|
| Amazon Web Services | Cloud infrastructure hosting |
| Google Cloud Platform | AI/ML model inference |
| Stripe | Payment processing |
| Twilio / SendGrid | Email and SMS delivery |
| Okta | Identity and access management |
| Datadog | Infrastructure monitoring and logging |
Have Security Questions?
Our support team is available to answer questions about our compliance program, security practices, or to provide additional documentation under NDA.
Trust Center last updated: September 2026
Our security practices are designed to align with industry compliance frameworks.
