Third Party Index

Snapshot 19747

Document
Trust center
URL
https://trust.glassbox.com/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
153696 bytes
SHA-256 (raw)
9f7fb71db163f69fdc4a6262cff03c984bf72663922b8aea21e7d0255914d603
SHA-256 (normalized text)
f78da44e3e60ab5ad16fadda34e43ae278361520f74e5e61c55b58e2a8074fe0

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to navigationSkip to main content
Welcome to the Glassbox Trust Center
At Glassbox, earning your trust through honesty, empathy, and professionalism is the foundation of everything we do. We know that when it comes to your data and your customers' experiences, the stakes are incredibly high.
We built this Trust Center to provide you with a clear, transparent view into how we protect your information. Because we always strive to walk in our customers' shoes, we've designed this space to make it as effortless as possible for you to find the security, privacy, and compliance details you need to feel confident in our partnership.
[email protected]
Privacy PolicyOpens in new tab
AWS Marketplace listingOpens in new tab
We believe that true partnership requires acting with integrity and respect at every level. If you have any questions or need further documentation, our team is ready to help.
Compliance
ISO 27001:2022
ISO 27701:2025
ISO 27017
ISO/IEC 42001:2023
SOC 2
CSA STAR LEVEL-1
GDPR
CCPA
HIPAA
Resources
View all
Microsoft Marketplace
Microsoft Marketplace Link
Opens in new tab
ISO Certificates
View 1 more
Self-Assessments
CAIQv4.0.2Opens in new tab
STAR Registry for Glassbox
Opens in new tab
SOC 2 Type II
SOC2 Type2 Report
SOC 2 Bridge letter 2026
Glassbox Architecture
Glassbox Cloud Data Flow
Glassbox AI
GIA - Responsible AI
AI-0001-01 AI Policy Framwork.pdf
Data Privacy
Glassbox Privacy by Design
IS-0010-02 Data Retention and Disposal policy.pdf
IS-0023-02 Global Data Security Privacy Policy.pdf
Security Policies
IS-0025-02 Business Continuity Policy and Disaster Recovery Policy.pdf
IS-0016-02 Physical and environmental security.pdf
IS-0034-01 Background checks and Reoccurring Background Checks Policy.pdf
IS-0011-02 Cloud Production- Encryption (Cryptography) Policy.pdf
View 12 more
Environmental Policies
IS-0035-01 Glassbox Environmental Policy
Social Policies
IS-0036-01 Glassbox Social Policy.pdf
IS-0028-01 Fraud Prevention Policy.pdf
Web Application Penetration Test
Web Application Penetration Test 2026
Controls
View all
Platform Architecture
Deployment offerings
Tenant Isolation
Infrastructure security
Business Continuity & Disaster Recovery
Capacity Management
Clock Synchronization
View 7 more Infrastructure security controls
Application security
Web Application Firewall (WAF)
Vulnerability Management
Segregation of Environments
View 4 more Application security controls
Data and privacy
Data Masking
Data Minimization
Data Protection Officer (DPO)
View 2 more Data and privacy controls
Organizational Security
Security Roles & Responsibilities
Employee Background Checks
Security, Privacy & AI Awareness Training
View 3 more Organizational Security controls
Responsible AI
ISO/IEC 42001 Certified
AI Governance
AI Security & Data Protection
View 2 more Responsible AI controls
Subprocessors
View all
AWS
•
Cloud Hosting
According to the AWS region chosen by the customer among the following options: Ireland (EU); Northern Virginia(USA); Singapore
IaaS provider for the production application and holder of all application data storage and processing.
Microsoft Azure
•
Cloud Hosting
Northern Virginia (USA)
IaaS provider for the production application and holder of all application data storage and processing
Okta
•
SSO
AWS (USA)
Only applicable where customer has chosen to use Glassbox services for user management instead of integrating with its own SSO service.
FAQ
View all
Updates
View all
Compliance
Upcoming SOC 2 Audit and Report
Published September 28, 2026
In October, we are starting the SOC 2 audit which covers the previous year. We expect to receive the new report in January 2027.
The bridge letter currently available in the portal attests that nothing material has changed since the last SOC 2 report was issued.
Please note that a SOC 2 report is an audit report that usually covers a defined period, typically one year, and therefore looks back at the previous audit period.