Snapshot 20801
Normalized text
Scripts and page chrome removed; this is what change detection compares.
™ Schedule a Demo Security How we protect your data, and what we commit to contractually Our security commitments Every commitment on this page is written into our Terms of Service, not just described in marketing copy. Current customers can request our latest reports directly. Your data is never used to train AI models OpenGRC includes AI features that process your data at your direction. We do not use Customer Data to train, fine-tune, or otherwise improve artificial intelligence or machine learning models, and we do not permit our subprocessors to do so. Outputs generated from your data are your data. This is a contractual commitment (Terms of Service §4.11), not a policy we can quietly revise. Independent audit and testing SOC 2 Type II. We maintain a SOC 2 Type II examination of the service, performed at least annually by an independent auditor. Our most recent report is available to customers on request, under NDA. Annual penetration testing. The service is penetration tested at least annually by an independent third party. How your data is protected Encrypted in transit and at rest using industry-standard encryption. Logically isolated. Your data lives in a dedicated database schema and storage location, encrypted with a key unique to your instance. Data residency. Your data is stored in the region specified in your Order Form, and in the United States if none is specified. You own your data. You retain all right, title and interest in it. We acquire no rights beyond those needed to run the service. Incident response We notify you of any security incident without undue delay, and in any event within 24 hours of confirming it. That notice describes what happened, which categories of your data were affected, and what we have done or will do in response. We provide updates as the investigation proceeds, and cooperate with any notification obligations you have under applicable law. Availability We commit to 99.5% monthly uptime, excluding scheduled maintenance windows. The full terms, including exclusions, are in §11.4 of our Terms of Service. Subprocessors We use subprocessors, including hosting and AI providers, to deliver the service. Each is bound by written agreement to data protection and confidentiality obligations no less protective than our own, and we remain responsible for their performance. A current list is available to customers on request. HIPAA OpenGRC is not a general repository for Protected Health Information. Where you are a HIPAA Covered Entity or Business Associate, we offer a Business Associate Agreement (BAA), and the BAA governs the handling of PHI. Access control and authentication Single sign-on with Microsoft Entra ID, Okta, Google and Auth0. Passkeys and WebAuthn, plus two-factor authentication, for accounts that do not go through SSO. Magic links for external parties — vendors, auditors and staff in the portals — so nobody needs an account they will forget. Role-based access control with a permission matrix you edit yourself, rather than a fixed set of roles someone else decided on. Separation and accountability Six isolated panels — the application, admin, vendor portal, auditor portal, user portal and the public trust center — so an external party never lands in your environment. Activity logging on every record, so changes are attributable long after everyone has forgotten making them. Soft deletes with restore throughout, because the wrong thing does occasionally get deleted. Portals have a kill switch, and auditor access is time-bounded and revocable. Reporting a vulnerability If you believe you have found a security issue in OpenGRC, please tell us through our contact page. Our machine-readable security contact is published at /.well-known/security.txt. More detail Our Trust Center holds current documentation — and the same trust center feature is included with OpenGRC Enterprise. See also our Privacy Policy and Terms of Service.