Third Party Index

Snapshot 20826

Document
Subprocessor list
URL
https://trust.orgvue.com/?itemUid=e3fae2ca-94a9-416b-b577-5c90e382df57
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
514911 bytes
SHA-256 (raw)
cd9809921bc341e7aaa61063318437dcaf500a3e680172b50ff26607c7986cc8
SHA-256 (normalized text)
065cd2a38c856db308d3852ed1d5dfaef651b55bd014475228da7c4672bfb4e6

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust Center
Start your security review
View & download sensitive information
Ask for information
Overview
Welcome to Orgvue's Trust Center where you can find out all about our security and compliance standards. Orgvue is committed to ensuring the highest security and compliance standards built directly into our platform and our operations. The confidentiality, integrity, availability and privacy of your people data is paramount to Orgvue.
Compliance
SOC 2
ISO/IEC 27001:2022
ISO/IEC 27018:2019
ISO/IEC 42001:2023
ISO 14001:2015
TX-RAMP
CSA STAR
Cyber Essentials
FSQS
JOSCAR
ISO/IEC 27001 SoA
AI Pact
Orgvue is reviewed and trusted by
Aviva plc
Bank of Ireland
Brightstar Lottery
Danone
Dow
Mars, Incorporated
M&T Bank
Phoenix Group
Tesco
Documents
Featured Documents
DOCUMENTSSecurity Summary
AIAI Security Summary
REPORTSSecurity Overview
AIAI Security Overview
DOCUMENTSData Flow Diagram
AIHenshaw Assistant: Data Flow
COMPLIANCESOC 2
COMPLIANCEISO/IEC 27001:2022
REPORTSPentest Report
REPORTSNetwork Diagrams
COMPLIANCEISO/IEC 27018:2019
COMPLIANCECSA STAR
Legal
Subprocessors
Accessibility Statement
Customer Audit Rights
View more
Data Privacy
Cookies
Data Breach Notifications
Data Privacy Officer
View more
AI
AI Security Summary
Orgvue MCP Security Overview
AI Security Overview
View more
ESG
Anti-Bribery and Corruption
Anti-Modern Slavery
Carbon Neutrality
View more
Reports
Disaster Recovery Database Restore Test Report
Network Diagrams
Orgvue Blender Overview
View more
Policies
Acceptable Use Policy
AI Policy
AI Development Policy
View more
Self-Assessments
CAIQ
SIG
UpGuard Default CyberRisk Questionnaire
Data Security
Access Monitoring
Data Backups
Data Erasure
View more
Product Security
Audit Logging
Data Security
Multi-Factor Authentication
View more
App Security
Code Analysis
Credential Management
Web Application Firewall
Security Grades
Qualys SSL Labs
Orgvue North America
A+
Orgvue Europe
A+
Orgvue Asia Pacific
A+
UpGuard
Orgvue Hosting Environments
912
Access Control
Data Access
Logging
Remote Access
BC/DR
Alternate Processing/Storage Site
Business Continuity Plan (BCP)
Data Backup/Backup Protection
View more
Endpoint Security
Disk Encryption
DNS Filtering
Endpoint Detection & Response
Network Security
Egress Filtering
Firewall
IDS/IPS
View more
Corporate Security
Asset Management Practices
Email Protection
Employee Training
View more
Infrastructure
Status Monitoring
Amazon Web Services
Anti-DDoS
View more
Risk Profile
Data Access LevelRestricted
Recovery Time Objective4 hours
Recovery Point Objective1 hour
View more
Knowledge Base (FAQ)
Are Web Application Firewalls (WAF) implemented for Orgvue?
Are Orgvue systems hardened based on industry best practices like CIS?
What training materials and documentation are provided? Do you offer on-site or remote training for your customers?
Is the Orgvue information security program audited to ensure continued control compliance and adherence to policies?
Environment data replication: Please explain if and how your system supports the copying of production data (specified or full) to dev and test environments , and the scrambling /desensitisation of data within this process.
View more
Trust Center Updates
Orgvue Achieves ISO/IEC 42001 Certification
Compliance
Orgvue is pleased to announce that it has achieved certification to ISO/IEC 42001:2023, the world's first international standard for Artificial Intelligence Management Systems (AIMS). The certification provides independent assurance that Orgvue has established and maintains a structured framework for the governance, oversight and continual improvement of AI technologies used within its platform, supporting responsible innovation in organizational design, workforce planning and transformation.
As AI becomes increasingly important in workforce-related decision-making, customers need confidence that appropriate controls, accountability and human oversight are in place. ISO/IEC 42001 certification demonstrates Orgvue's commitment to managing AI risks responsibly, maintaining transparency, and embedding governance into the design and operation of its AI capabilities. This achievement builds on Orgvue's broader security, privacy and compliance program and provides customers with additional assurance that AI-enabled services are managed in line with internationally recognized best practices.
Update to Orgvue Security Provisions
General
As part of Orgvue’s ongoing commitment to continually improve security an update to the Orgvue Security Provisions has been released.
In summary the changes include:
In section 2.9, a change to the definition of Multi-Tenanted. We’re improving how we protect your data within our multi-tenant architecture. Previously, our platform described customer data separation as achieved through logical segregation and encryption. We’re now introducing Row-Level Security (RLS) — an advanced method that ensures each customer can only access their own data, even within shared database environments. RLS enhances our existing logical data segregation by enforcing data access policies directly at the database level, providing more granular control and transparency over how data is isolated. While the description of our architecture has been refined to reflect this technical enhancement, our commitment to safeguarding customer data remains unchanged. This update strengthens the robustness of our security model and aligns with modern best practices in SaaS data protection.
In section 4, we have removed the commitment to validate education and professional certifications as part of background checks for new employees. This check is completed for specific roles only.
In section 6.6, an amendment has been made to reflect the support for SCIM (System for Cross-domain Identity Management), which the Orgvue platform now provides.
In section 7.1 an amendment has been made indicating that TLS 1.3 is now the default TLS encryption version (TLS 1.2 remains supported).
In section 9, an amendment has been made providing commitment to the remediation of vulnerabilities, in line with Orgvue’s vulnerability management process. Remediation timelines are aligned to commonly understood industry best practices.
New SOC 2 Type 2 Report Available for Download
Compliance
We’re pleased to announce that Orgvue has successfully completed its SOC 2 Type 2 audit for the period 01-Oct-2024 - 30-Sep-2025. Orgvue's latest SOC 2 Type 2 report is now available to view and download from our Trust Center. This report demonstrates our commitment to maintaining the highest standards of security for your data.
New SOC 2 Type 2 Report Available for Download
Compliance
Orgvue's latest SOC 2 Type 2 report is now available to view and download from our Trust Center. This report demonstrates our ongoing commitment to data security at Orgvue.
Orgvue New Sub-processor Notification: Snowflake
Subprocessors
Orgvue is adding a new Sub-processor, Snowflake. Snowflake will perform product usage analytics and will process customer email addresses only.
Name: Snowflake
Location of Processing: UK
Website: https://www.snowflake.com/
Purpose of Processing: Product Usage Analytics
Type of Personal Data: customer email addresses
For further information please contact [email protected]
If you need help using this Trust Center, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue