Snapshot 19747
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to navigationSkip to main content Welcome to the Glassbox Trust Center At Glassbox, earning your trust through honesty, empathy, and professionalism is the foundation of everything we do. We know that when it comes to your data and your customers' experiences, the stakes are incredibly high. We built this Trust Center to provide you with a clear, transparent view into how we protect your information. Because we always strive to walk in our customers' shoes, we've designed this space to make it as effortless as possible for you to find the security, privacy, and compliance details you need to feel confident in our partnership. [email protected] Privacy PolicyOpens in new tab AWS Marketplace listingOpens in new tab We believe that true partnership requires acting with integrity and respect at every level. If you have any questions or need further documentation, our team is ready to help. Compliance ISO 27001:2022 ISO 27701:2025 ISO 27017 ISO/IEC 42001:2023 SOC 2 CSA STAR LEVEL-1 GDPR CCPA HIPAA Resources View all Microsoft Marketplace Microsoft Marketplace Link Opens in new tab ISO Certificates View 1 more Self-Assessments CAIQv4.0.2Opens in new tab STAR Registry for Glassbox Opens in new tab SOC 2 Type II SOC2 Type2 Report SOC 2 Bridge letter 2026 Glassbox Architecture Glassbox Cloud Data Flow Glassbox AI GIA - Responsible AI AI-0001-01 AI Policy Framwork.pdf Data Privacy Glassbox Privacy by Design IS-0010-02 Data Retention and Disposal policy.pdf IS-0023-02 Global Data Security Privacy Policy.pdf Security Policies IS-0025-02 Business Continuity Policy and Disaster Recovery Policy.pdf IS-0016-02 Physical and environmental security.pdf IS-0034-01 Background checks and Reoccurring Background Checks Policy.pdf IS-0011-02 Cloud Production- Encryption (Cryptography) Policy.pdf View 12 more Environmental Policies IS-0035-01 Glassbox Environmental Policy Social Policies IS-0036-01 Glassbox Social Policy.pdf IS-0028-01 Fraud Prevention Policy.pdf Web Application Penetration Test Web Application Penetration Test 2026 Controls View all Platform Architecture Deployment offerings Tenant Isolation Infrastructure security Business Continuity & Disaster Recovery Capacity Management Clock Synchronization View 7 more Infrastructure security controls Application security Web Application Firewall (WAF) Vulnerability Management Segregation of Environments View 4 more Application security controls Data and privacy Data Masking Data Minimization Data Protection Officer (DPO) View 2 more Data and privacy controls Organizational Security Security Roles & Responsibilities Employee Background Checks Security, Privacy & AI Awareness Training View 3 more Organizational Security controls Responsible AI ISO/IEC 42001 Certified AI Governance AI Security & Data Protection View 2 more Responsible AI controls Subprocessors View all AWS • Cloud Hosting According to the AWS region chosen by the customer among the following options: Ireland (EU); Northern Virginia(USA); Singapore IaaS provider for the production application and holder of all application data storage and processing. Microsoft Azure • Cloud Hosting Northern Virginia (USA) IaaS provider for the production application and holder of all application data storage and processing Okta • SSO AWS (USA) Only applicable where customer has chosen to use Glassbox services for user management instead of integrating with its own SSO service. FAQ View all Updates View all Compliance Upcoming SOC 2 Audit and Report Published September 28, 2026 In October, we are starting the SOC 2 audit which covers the previous year. We expect to receive the new report in January 2027. The bridge letter currently available in the portal attests that nothing material has changed since the last SOC 2 report was issued. Please note that a SOC 2 report is an audit report that usually covers a defined period, typically one year, and therefore looks back at the previous audit period.