Third Party Index

Snapshot 27842

Document
Trust center
URL
https://trust.esper.com/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
65867 bytes
SHA-256 (raw)
0d6b2ef302303f0758866fd6a05c6927a5f77191b42f22af21a5989bafaa97fb
SHA-256 (normalized text)
4c45d77939b449c75746db6b7f26595b254580c3c8029ac18c32b6e6cd15e95f

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Compliance
Documentation of our compliance against global standards including certifications, attestations, and audit reports.
Documents
Policies
Subprocessors
Amplitude
Product analytics
Data location: United States
Datadog
Metrics, observability, application performance monitoring, synthetic testing, security information and event management, log aggregation, monitoring
Data location: Virginia
Amazon Web Services
Cloud infrastructure and security
Data location: Ohio, California
Knowledge Base (FAQ)
5
Esper operates primarily as a remote-first company with data center security handled by our cloud infrastructure provider, Amazon Web Services (AWS). Please rely on reports, certifications, and attestations from AWS when assessing physical security controls.
Employees are required to follow strict physical security practices when working remotely, including never leaving work devices unattended, keeping devices locked when away, and storing any sensitive paper documents in secure locations.
Yes, Esper implements comprehensive encryption for data both at rest and in transit. Data at rest is stored on encrypted volumes using encryption keys managed by Amazon Web Services (AWS). All external data transmission must be encrypted end-to-end using encryption keys managed by AWS, including cloud infrastructure and third-party vendors. Esper requires the use of FIPS 140-2 and FIPS 140-3 validated cryptographic modules for strong encryption algorithms like AES-256 for data encryption keys and TLS 1.2+ for transit encryption.
Customer data is only handled by authorized sub-processors located in the continental United States.
Yes, Esper supports both SAML 2.0 and OpenID Connect single sign-on flows.
Automatic account provisioning is supported with the SCIM 2.0 protocol, which is easily configurable within popular identity provider systems like Azure Entra ID and Okta. Groups can be mapped to roles and license types within Esper.
Esper offers both multi-tenant and single-tenant deployment models. All customer data is logically separated at the database table level. Authorization checks are in place prior to database retrieval to limit access to data belonging to your tenant. Automated web application testing and third-party penetration testing is conducted to ensure these boundaries are secure.