Trust center

A trust page that lists only what a company has achieved is a marketing page. This one names the gaps too, because you will find them in a security review anyway and it is better that you hear it here.

Including the parts we have not done yet.ACCOUNT INTELLIGENCE

Security posture

Encryption in transitTLS 1.3 on all endpointsIn place
Encryption at restAES-256 on database and object storageIn place
Access controlRole-based, least privilege, reviewed quarterlyIn place
Audit loggingAll record reveals and exports logged per userIn place
Data residencyUS or EU region, selected at account setupIn place
SSO and SCIMSAML 2.0 and directory provisioningEnterprise
Penetration testingAnnual third-party testPlanned
SOC 2 Type IIAudit not yet startedNot yet
ISO 27001Not yet pursuedNot yet

Subprocessors

Categories are listed here; named vendors and their regions are provided under NDA during procurement, and customers are notified before a new subprocessor is added.

Cloud hostingApplication and database, region-pinned
Email verificationSMTP validation at reveal time
Contact data providersLicensed direct dial and email sources
AnalyticsProduct usage, no contact data transmitted

Retention

Contact recordsHeld while the lawful basis stands. Deleted on request within 30 days.
Signal historyRolling 90 days. Older readings aggregated then discarded.
Customer account dataFor the contract term plus 90 days.
Audit logs12 months.
Suppression listRetained indefinitely — that is how we keep a deletion honoured.