Third Party Index

Snapshot 21620

Document
Security page
URL
https://security.circleback.ai/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
98264 bytes
SHA-256 (raw)
090f28cc787fb90a2d9d04f2a4674792a810fffe07a7ff892f62f9bd1a08b58f
SHA-256 (normalized text)
c3194be9e55924a0e0f729e141d2dc005fcc5072a4d36f9890fc19467171e603

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Monitored and Powered by
circleback.ai
[email protected]
Compliance overview
Current compliance status across frameworks
SOC 2 Type 2
Compliant
HIPAA
Compliant
EU-U.S. Data Privacy Framework
Compliant
GDPR
Compliant
Featured documents
Key security and compliance documentation
Circleback - SOC 2 Type II Report - May'25 to July'25
Request access
Subprocessors
Request access
Q3 2026 Circleback Pentest
Request access
View all documents
Compliance Program
An overview of security controls in place
Access Control and Authorization
Access management policy established
Employee access regularly reviewed
MFA required for critical services
Password management policy enforced
Password management policy established
Data Management and Protection
Consent for collecting and managing data obtained
Data encrypted at rest
Data inventory maintained
Data management and retention policy established
Data transfer mechanisms established
External privacy inquiries managed
Privacy disclosure and notification mechanisms established
Privacy policy created and maintained
Disaster Recovery
Automated backups enabled
Business continuity and disaster recovery policy established
Data recovery process established
Disaster recovery plans tested
Recovery data isolated
Email Security
DMARC policy and verification used
Email account access restricted
Email settings block malicious content
Endpoint Security
Anti-malware deployed on end-user devices
Data encrypted on end-user devices
Firewall maintained on end-user devices
Infrastructure Security
Active discovery tools used
Buckets not exposed publicly
Configuration management system established
Firewall restricts public access to infrastructure
Infrastructure changes logged
Infrastructure changes require review
Network infrastructure continuously updated
Unauthorized assets addressed and removed
Unique production database authentication enforced
Web Application Firewall (WAF) used
Monitoring and Incident Response
Adequate audit log storage maintained
Audit log management process maintained
Audit logs collected
Breach notification process established
Incident response exercises performed
Incident response policy established
Incident review process implemented
Infrastructure performance monitored
Log management used
Network infrastructure monitored
Organizational Security
Acceptable use policy established
Asset inventory maintained
Asset management policy established
Code of conduct established
Company security commitments externally communicated
Confidentiality Agreement acknowledged by contractors
Confidentiality Agreement acknowledged by employees
External support resources available (i.e., documentation)
Internal privacy policies established
Internal security audit performed
Offboarding process established
Onboarding process established
Password manager used
Performance evaluations conducted
Physical access restricted
Physical security policy established
Reference checks performed for employees
Relevant authorities identified
Roles and responsibilities specified
Sanction policy established
Security awareness training conducted
Security official assigned
Service description communicated
Software development lifecycle established
System changes externally communicated
System changes internally communicated
Vendor agreements established
Workstation use and security policy established
Risk Management
Risk assessments performed
Risk management policy established
Vendor management program established
Vulnerability Management
Automated software patch management performed
Penetration testing findings remediated
Penetration testing performed within the last 12 months
Vulnerability management policy established