Third Party Index

Snapshot 18648

Document
Trust center
URL
https://trust.suralink.com/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
75732 bytes
SHA-256 (raw)
3fd773b08a53d7d4f7e43496c8174ed1759fd944c573199d2247131853d09ca7
SHA-256 (normalized text)
f7548b239334650cf429dd17f93f618d34d5c8bc8551a1f463964a46666de38f

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Suralink Trust Center
Welcome to the Suralink Trust Center
Published on Feb 12, 2026
At Suralink, security and transparency are our top priorities. This Trust Center is your go-to resource for information on our security practices, compliance certifications, and data protection policies. Here, you’ll find the latest updates, documentation, and insights related to how we keep your data safe.
We’re committed to providing a secure and reliable platform, and this page is designed to give you the confidence and clarity you need. Explore the resources below, and if you have additional questions beyond the information provided here, please reach out to us at [email protected].
Compliance
To review our detailed security controls, you can request access to our SOC 2 Type 2 report for the prior year which provides an in-depth look at our security, availability, and confidentiality measures.
Security
Security Controls
While this section provides an overview of some of the controls we have in place to protect customer data and ensure the security of our platform, a full review of our security practices is available in our SOC 2 report. To access the complete details, please request our SOC 2 report above.
App Security
Access Deprovisioning
Session Lock
Unique Accounts Used
Vulnerability Management
Data Security
Change Management Policy
Daily Database Backups
Encryption at Rest
Infrastructure Security
Automated Security Updates
Autoscaling
Backup Monitoring
Backup Policy
Backup Restore Testing
Credentials Rotation
Cryptographic Key Rotation
Network Security
Access Provisioning
Account Lockout after Failed Logins
Anti-Malware Capabilities and Automatic Updates
Audit Logging
Denial of Public SSH
Organization Security
Background Checks
Board Charter Documented
Business Continuity Plan
Code Review Process
Incident Response Plan
Security Training
System Access Control Policy
Product Security
Annual Penetration Test
Code of Conduct
Disaster Recovery Plan
Hard-Disk Encryption
Logging/Monitoring
MFA on Accounts
Password Policy
Terms of Service
Subprocessors
Amazon Web Services
Cloud Hosting
Data location: N. Virginia, Central Canada, Frankfurt.
Google Cloud Platform
Cloud infrastructure and AI capabilities
Data location: USCentral1
Atlassian
Collaboration
Data location: California
Intercom
Communication
Data location: North Virginia
Hubspot
Automation
Data location: US East
Pendo
Analytics
Data location: North Virginia
Frequently Asked Questions
7
Suralink employs multiple security measures to protect sensitive client information:
Multi-Factor Authentication (MFA): Adds an extra layer of security by requiring multiple forms of verification during login.
Inactivity Timeout: Automatically logs users out after a period of inactivity to prevent unauthorized access.
Encrypted Third-Party Access: Ensures that any third-party access to data is encrypted and secure.
Access Restriction by Role or Engagement: Limits data access based on user roles and specific engagements to ensure that only authorized personnel can view or modify information.
SSL with AES 256-bit Encryption: Utilizes Secure Sockets Layer (SSL) technology combined with Advanced Encryption Standard (AES) 256-bit encryption to protect data during transmission.
SOC1, SOC2, and SOC3 Compliant Data Centers: Stores data in data centers that comply with Service Organization Control (SOC) standards, ensuring high levels of security and operational integrity.
All documents uploaded to Suralink are secured with AES-256 bit encryption. Additionally, sensitive information such as client organization names, engagement names, and user comments are encrypted at rest using the same AES-256 bit encryption standard.
Suralink encrypts and backs up all stored data offsite daily. To prevent accidental deletions, a two-stage "click then confirm" deletion system is implemented. Furthermore, an audit trail logs all system activity by username and IP address, facilitating data recovery and accountability.
Yes, Suralink performs regular vulnerability and penetration security tests. These include both internal and external scans conducted by multiple third-party experts to ensure the highest levels of security.
Suralink adheres to several data privacy regulations and standards, including:
SOC2: Developed by the American Institute of CPAs (AICPA), SOC 2 defines criteria for managing customer data based on five "trust service principles"—security, availability, processing integrity, confidentiality, and privacy.
General Data Protection Regulation (GDPR): A legal framework that sets guidelines for the collection and processing of personal information from individuals who live in the European Union (EU).
California Consumer Privacy Act (CCPA): A state-wide data privacy law that regulates how businesses worldwide are allowed to handle the personal information of California residents.
By complying with these standards, Suralink ensures that data privacy protections meet stringent compliance requirements.
About Suralink
Suralink provides accounting and other professional service firms with a single, secure platform to collaborate with clients, exchange documents at scale, and track the progress of engagements. With enterprise-grade security and an easy-to-use interface, Suralink's award-winning client interaction portal helps firms increase efficiency and improve their relationships with their clients.
Address
10 Exchange Place, Suite 300
Salt Lake City, Utah 84111
United States
Contact
[email protected]
Privacy details
Privacy URL