What we do about your data, and what we have not finished.
Bid documents, contracts and payroll records carry real exposure. This page states our controls precisely — including the certifications we do not hold, because your reviewer will ask.
Stated exactly, including the gaps
- SOC 2 Type I
- Attested
- SOC 2 Type II
- In observation
- Penetration test
- Annual
- ISO 27001
- Not held
- Questionnaire turnaround
- 5 days
Reports, the penetration test summary and our subprocessor list are available under NDA.
Compliance posture, stated exactly.
SOC 2 is an attestation, not a certification, and Type I covers control design rather than operating effectiveness. We use the terms properly here so you can rely on them.
SOC 2 Type I
AttestedIndependent report on the design of our access, change and vendor-management controls. Available under NDA.
SOC 2 Type II
In observationObservation window under way; report expected Q4 2026. We do not describe ourselves as Type II until that report exists.
Penetration test
AnnualThird-party test of our internal systems. Executive summary available under NDA; full report to enterprise clients on request.
ISO 27001
Not heldWe are not ISO 27001 certified and have no current timeline. If your procurement requires it, tell us early rather than late.
HIPAA
Not applicable todayHIPAA has no certifying body. We do not currently handle protected health information; this changes when the healthcare vertical opens and we will publish the BAA position then.
PCI-DSS
Aligned handlingWe are not a certified service provider. Where a seat touches payment data it is under scoped controls on hardened devices, and we will document the arrangement for your assessor.
If a requirement on your side is not met above, say so in the first conversation. We will either tell you our timeline or tell you we are not the right vendor — we will not let it surface during contracting.
The four places a staffing arrangement leaks.
People, devices, access and data. Each list below is what we actually enforce, not what we aspire to.

People
- Government ID, degree, and employment history verified before hiring
- Live video identity check at two separate stages of hiring
- Criminal background screening where local law permits
- NDA and IP assignment signed as a condition of employment
- Annual security awareness training, with completion tracked
Devices
- Company-issued endpoints only; personal machines are not permitted
- Full-disk encryption enforced and monitored
- Endpoint detection and response agent on every device
- Configuration benchmarked to CIS Level 2
- Screen lock, patch currency and USB policy enforced centrally
Access
- Your tenant, your permissions, your audit log — we do not proxy your data
- Least-privilege scoping per project, reviewed quarterly
- Credentials stored in a password manager, never in email or chat
- MFA required on every system that supports it
- Centralized revocation within one business day of offboarding
Data
- No client project data stored on our own infrastructure by default
- Work product remains your property under the master agreement
- Customer DPAs signed on request; our standard DPA available on request
- Subprocessor list published and updated with 30 days' notice of change
- Incident notification commitment stated in the agreement, not left implied
What we will send you.
Most of it requires an NDA, which we will turn around same day. None of it requires a sales call first.
SOC 2 Type I report
Under NDA
Penetration test summary
Under NDA
Subprocessor list
On request
Standard DPA
On request
Completed CAIQ / SIG Lite
Under NDA
Insurance certificates
On request
What reviewers ask us.
Answered the way we would answer on the call.
Not covered here? Ask us directly — a person answers, usually same day.
Send us your questionnaire
Five business days for a completed questionnaire, no charge, and we will join the review call. Enterprise programs run this in parallel with recruiting.