Snapshot 18648
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Suralink Trust Center Welcome to the Suralink Trust Center Published on Feb 12, 2026 At Suralink, security and transparency are our top priorities. This Trust Center is your go-to resource for information on our security practices, compliance certifications, and data protection policies. Here, you’ll find the latest updates, documentation, and insights related to how we keep your data safe. We’re committed to providing a secure and reliable platform, and this page is designed to give you the confidence and clarity you need. Explore the resources below, and if you have additional questions beyond the information provided here, please reach out to us at [email protected]. Compliance To review our detailed security controls, you can request access to our SOC 2 Type 2 report for the prior year which provides an in-depth look at our security, availability, and confidentiality measures. Security Security Controls While this section provides an overview of some of the controls we have in place to protect customer data and ensure the security of our platform, a full review of our security practices is available in our SOC 2 report. To access the complete details, please request our SOC 2 report above. App Security Access Deprovisioning Session Lock Unique Accounts Used Vulnerability Management Data Security Change Management Policy Daily Database Backups Encryption at Rest Infrastructure Security Automated Security Updates Autoscaling Backup Monitoring Backup Policy Backup Restore Testing Credentials Rotation Cryptographic Key Rotation Network Security Access Provisioning Account Lockout after Failed Logins Anti-Malware Capabilities and Automatic Updates Audit Logging Denial of Public SSH Organization Security Background Checks Board Charter Documented Business Continuity Plan Code Review Process Incident Response Plan Security Training System Access Control Policy Product Security Annual Penetration Test Code of Conduct Disaster Recovery Plan Hard-Disk Encryption Logging/Monitoring MFA on Accounts Password Policy Terms of Service Subprocessors Amazon Web Services Cloud Hosting Data location: N. Virginia, Central Canada, Frankfurt. Google Cloud Platform Cloud infrastructure and AI capabilities Data location: USCentral1 Atlassian Collaboration Data location: California Intercom Communication Data location: North Virginia Hubspot Automation Data location: US East Pendo Analytics Data location: North Virginia Frequently Asked Questions 7 Suralink employs multiple security measures to protect sensitive client information: Multi-Factor Authentication (MFA): Adds an extra layer of security by requiring multiple forms of verification during login. Inactivity Timeout: Automatically logs users out after a period of inactivity to prevent unauthorized access. Encrypted Third-Party Access: Ensures that any third-party access to data is encrypted and secure. Access Restriction by Role or Engagement: Limits data access based on user roles and specific engagements to ensure that only authorized personnel can view or modify information. SSL with AES 256-bit Encryption: Utilizes Secure Sockets Layer (SSL) technology combined with Advanced Encryption Standard (AES) 256-bit encryption to protect data during transmission. SOC1, SOC2, and SOC3 Compliant Data Centers: Stores data in data centers that comply with Service Organization Control (SOC) standards, ensuring high levels of security and operational integrity. All documents uploaded to Suralink are secured with AES-256 bit encryption. Additionally, sensitive information such as client organization names, engagement names, and user comments are encrypted at rest using the same AES-256 bit encryption standard. Suralink encrypts and backs up all stored data offsite daily. To prevent accidental deletions, a two-stage "click then confirm" deletion system is implemented. Furthermore, an audit trail logs all system activity by username and IP address, facilitating data recovery and accountability. Yes, Suralink performs regular vulnerability and penetration security tests. These include both internal and external scans conducted by multiple third-party experts to ensure the highest levels of security. Suralink adheres to several data privacy regulations and standards, including: SOC2: Developed by the American Institute of CPAs (AICPA), SOC 2 defines criteria for managing customer data based on five "trust service principles"—security, availability, processing integrity, confidentiality, and privacy. General Data Protection Regulation (GDPR): A legal framework that sets guidelines for the collection and processing of personal information from individuals who live in the European Union (EU). California Consumer Privacy Act (CCPA): A state-wide data privacy law that regulates how businesses worldwide are allowed to handle the personal information of California residents. By complying with these standards, Suralink ensures that data privacy protections meet stringent compliance requirements. About Suralink Suralink provides accounting and other professional service firms with a single, secure platform to collaborate with clients, exchange documents at scale, and track the progress of engagements. With enterprise-grade security and an easy-to-use interface, Suralink's award-winning client interaction portal helps firms increase efficiency and improve their relationships with their clients. Address 10 Exchange Place, Suite 300 Salt Lake City, Utah 84111 United States Contact [email protected] Privacy details Privacy URL