Compliance
4Independently audited and continuously evidenced against the standards our customers rely on.
EU AI Act
EU Artificial Intelligence (AI)I Act (Regulation (EU) 2024/1689)
- Valid through
- Sep 18, 2027
- Certificate
- 140426-1
GDPR
General Data Protection Regulation (GDPR)
- Valid through
- Sep 18, 2027
ISO 27001
ISO/IEC 27001:2022
- Valid through
- Sep 18, 2027
SOC 2
AICPA Trust Service Principles Service Organization Controls (SOC)
- Valid through
- Sep 18, 2027
Controls
275The safeguards we operate across our organization, technology, people, and facilities.
Inventory Management
Asset ManagementOrganization maintains an inventory of information systems, which is reconciled on a periodic basis.
Inventory Management: Applications
Asset ManagementOrganization maintains an inventory of application assets, which is reconciled on a periodic basis.
Inventory Labels
Asset ManagementOrganization assets are labeled and have designated owners.
Media Marking
Asset ManagementWhere applicable, Organization marks information system media indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information. Exemptions must be approved by management and remain in a specific controlled area.
Asset Transportation Authorization
Asset ManagementOrganization authorizes and records the entry and exit of systems at datacenter locations.
Maintenance of Assets
Asset ManagementEquipment maintenance is documented and approved according to management requirements.
Business Continuity Plan
Business ContinuityOrganization's business contingency plan is periodically reviewed, approved by management and communicated to relevant team members.
Continuity Testing
Business ContinuityOrganization performs business contingency and disaster recovery tests on a periodic basis and ensures the following: • tests are executed with relevant contingency teams • test results are documented • corrective actions are taken for exceptions noted • plans are updated based on results
Resources
54Policies, documentation, and reports that govern how we protect customer data.
Control Environment & Governance
Version 2026.2 · Reviewed May 18, 2026 · yearly
Design and Development Plan (DDP) Policy
Version 2026.2 · Reviewed Feb 24, 2026 · Annual
System Security & Privacy Plan (SSPP)
Version 2026.2 · Reviewed May 17, 2026 · Annual
Information Assurance Program (IAP) Policy
Version 2026.2 · Reviewed Feb 24, 2026 · Annual
Data & Asset Classification Policy
Version 2026.2 · Reviewed Feb 24, 2026 · annual
Log and Event Log Review & Analysis Policy
Version 2026.2 · Reviewed Aug 26, 2026 · Monthly
Automated Event Escalation & Reporting Policy
Version 2026.2 · Reviewed Feb 24, 2026 · Annual
Intellectual Property (IP) Infringement Assessment of Artificial Intelligence and Autonomous Technologies (AAT)
Version 2026.2 · Reviewed Feb 24, 2026 · Annual
Subprocessors
12Third-party providers that process customer data on our behalf, and where they operate.
Plaid
Software as a ServiceOAuth app authorized by users
HubSpot
Software as a ServiceInbound marketing and sales platform
Tailscale
Software as a ServiceOAuth app authorized by users
OpenRouter
Software as a ServiceOAuth app authorized by users
Langfuse
Software as a ServiceOAuth app authorized by users
Twilio
Software as a ServiceOAuth app authorized by users
Noru
Software as a ServiceOAuth app authorized by users
ElevenLabs
Software as a ServiceOAuth app authorized by users
Questions about our security?
We're glad to help your security and procurement teams move quickly.