Snapshot 20826
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Trust Center Start your security review View & download sensitive information Ask for information Overview Welcome to Orgvue's Trust Center where you can find out all about our security and compliance standards. Orgvue is committed to ensuring the highest security and compliance standards built directly into our platform and our operations. The confidentiality, integrity, availability and privacy of your people data is paramount to Orgvue. Compliance SOC 2 ISO/IEC 27001:2022 ISO/IEC 27018:2019 ISO/IEC 42001:2023 ISO 14001:2015 TX-RAMP CSA STAR Cyber Essentials FSQS JOSCAR ISO/IEC 27001 SoA AI Pact Orgvue is reviewed and trusted by Aviva plc Bank of Ireland Brightstar Lottery Danone Dow Mars, Incorporated M&T Bank Phoenix Group Tesco Documents Featured Documents DOCUMENTSSecurity Summary AIAI Security Summary REPORTSSecurity Overview AIAI Security Overview DOCUMENTSData Flow Diagram AIHenshaw Assistant: Data Flow COMPLIANCESOC 2 COMPLIANCEISO/IEC 27001:2022 REPORTSPentest Report REPORTSNetwork Diagrams COMPLIANCEISO/IEC 27018:2019 COMPLIANCECSA STAR Legal Subprocessors Accessibility Statement Customer Audit Rights View more Data Privacy Cookies Data Breach Notifications Data Privacy Officer View more AI AI Security Summary Orgvue MCP Security Overview AI Security Overview View more ESG Anti-Bribery and Corruption Anti-Modern Slavery Carbon Neutrality View more Reports Disaster Recovery Database Restore Test Report Network Diagrams Orgvue Blender Overview View more Policies Acceptable Use Policy AI Policy AI Development Policy View more Self-Assessments CAIQ SIG UpGuard Default CyberRisk Questionnaire Data Security Access Monitoring Data Backups Data Erasure View more Product Security Audit Logging Data Security Multi-Factor Authentication View more App Security Code Analysis Credential Management Web Application Firewall Security Grades Qualys SSL Labs Orgvue North America A+ Orgvue Europe A+ Orgvue Asia Pacific A+ UpGuard Orgvue Hosting Environments 912 Access Control Data Access Logging Remote Access BC/DR Alternate Processing/Storage Site Business Continuity Plan (BCP) Data Backup/Backup Protection View more Endpoint Security Disk Encryption DNS Filtering Endpoint Detection & Response Network Security Egress Filtering Firewall IDS/IPS View more Corporate Security Asset Management Practices Email Protection Employee Training View more Infrastructure Status Monitoring Amazon Web Services Anti-DDoS View more Risk Profile Data Access LevelRestricted Recovery Time Objective4 hours Recovery Point Objective1 hour View more Knowledge Base (FAQ) Are Web Application Firewalls (WAF) implemented for Orgvue? Are Orgvue systems hardened based on industry best practices like CIS? What training materials and documentation are provided? Do you offer on-site or remote training for your customers? Is the Orgvue information security program audited to ensure continued control compliance and adherence to policies? Environment data replication: Please explain if and how your system supports the copying of production data (specified or full) to dev and test environments , and the scrambling /desensitisation of data within this process. View more Trust Center Updates Orgvue Achieves ISO/IEC 42001 Certification Compliance Orgvue is pleased to announce that it has achieved certification to ISO/IEC 42001:2023, the world's first international standard for Artificial Intelligence Management Systems (AIMS). The certification provides independent assurance that Orgvue has established and maintains a structured framework for the governance, oversight and continual improvement of AI technologies used within its platform, supporting responsible innovation in organizational design, workforce planning and transformation. As AI becomes increasingly important in workforce-related decision-making, customers need confidence that appropriate controls, accountability and human oversight are in place. ISO/IEC 42001 certification demonstrates Orgvue's commitment to managing AI risks responsibly, maintaining transparency, and embedding governance into the design and operation of its AI capabilities. This achievement builds on Orgvue's broader security, privacy and compliance program and provides customers with additional assurance that AI-enabled services are managed in line with internationally recognized best practices. Update to Orgvue Security Provisions General As part of Orgvue’s ongoing commitment to continually improve security an update to the Orgvue Security Provisions has been released. In summary the changes include: In section 2.9, a change to the definition of Multi-Tenanted. We’re improving how we protect your data within our multi-tenant architecture. Previously, our platform described customer data separation as achieved through logical segregation and encryption. We’re now introducing Row-Level Security (RLS) — an advanced method that ensures each customer can only access their own data, even within shared database environments. RLS enhances our existing logical data segregation by enforcing data access policies directly at the database level, providing more granular control and transparency over how data is isolated. While the description of our architecture has been refined to reflect this technical enhancement, our commitment to safeguarding customer data remains unchanged. This update strengthens the robustness of our security model and aligns with modern best practices in SaaS data protection. In section 4, we have removed the commitment to validate education and professional certifications as part of background checks for new employees. This check is completed for specific roles only. In section 6.6, an amendment has been made to reflect the support for SCIM (System for Cross-domain Identity Management), which the Orgvue platform now provides. In section 7.1 an amendment has been made indicating that TLS 1.3 is now the default TLS encryption version (TLS 1.2 remains supported). In section 9, an amendment has been made providing commitment to the remediation of vulnerabilities, in line with Orgvue’s vulnerability management process. Remediation timelines are aligned to commonly understood industry best practices. New SOC 2 Type 2 Report Available for Download Compliance We’re pleased to announce that Orgvue has successfully completed its SOC 2 Type 2 audit for the period 01-Oct-2024 - 30-Sep-2025. Orgvue's latest SOC 2 Type 2 report is now available to view and download from our Trust Center. This report demonstrates our commitment to maintaining the highest standards of security for your data. New SOC 2 Type 2 Report Available for Download Compliance Orgvue's latest SOC 2 Type 2 report is now available to view and download from our Trust Center. This report demonstrates our ongoing commitment to data security at Orgvue. Orgvue New Sub-processor Notification: Snowflake Subprocessors Orgvue is adding a new Sub-processor, Snowflake. Snowflake will perform product usage analytics and will process customer email addresses only. Name: Snowflake Location of Processing: UK Website: https://www.snowflake.com/ Purpose of Processing: Product Usage Analytics Type of Personal Data: customer email addresses For further information please contact [email protected] If you need help using this Trust Center, please contact us. Contact support If you think you may have discovered a vulnerability, please send us a note. Report issue