Third Party Index

Snapshot 40825

Document
Security page
URL
https://www.whalemate.com/en/security/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
50620 bytes
SHA-256 (raw)
244c434a92ad69bd3c7600c08e148935eb71543ed748b6f9184539e040059392
SHA-256 (normalized text)
e1d3a1855a2d0510e42175742935e1de43dd71892d216687c5cf3a9373396bd4

Normalized text

Scripts and page chrome removed; this is what change detection compares.

NewsWhalemate is ISO/IEC 27001:2022 certifiedSee Trust Center
How we protect your organization's data
Whalemate processes names, emails and simulation results of your employees. Where that data lives, who accesses it and under which controls. We only show what is certified today: ISO/IEC 27001:2022.
See the DPA
Architecture
Platform controls
Encryption
TLS 1.3 in transit and AES-256 at rest.
Access
SSO for the internal team, 2FA and least privilege.
Traceability
Access and change logging.
Continuity
Availability and recovery controls.
Residency
Hosting according to the scope agreed with the customer.
Retention
Retention and deletion policy defined in the DPA.
Employee data
What we collect and why
No individual metric is used for disciplinary purposes. That's in the contract, not only on this page.
Data	Why	Who sees it	Retention
Name and work email	Send the simulation and assign training	Program administrator	For the life of the contract
Simulation result	Compute the index and trigger reinforcement	Program administrator	24 months
Training progress	Compliance evidence	Administrator and audit	24 months
Area and role	Calibrate the scenario by profile	Aggregated, not individual	For the life of the contract
Responsible disclosure
Subprocessors
If you found a vulnerability, write to security@whalemate.com. We respond within 48 business hours. We do not take legal action against good-faith research.
Infrastructure on AWS. Transactional email and product analytics per the current DPA. The full list is updated with prior notice.
security@whalemate.com
In this module
Program capabilities
Access
2FA, session and brute-force
Whoever administers does not get in on a password alone. 2FA, session time, and brute-force lockout sit in the console, next to roles and the audit log.
Permissions
Users, roles and permissions
Who enters the console. Not roster SSO: operator access, with least privilege.
Trails
Audit log
Admin changes: who touched a permission, when. Course-completion logs also live on compliance.
Trust Center
How we handle names, emails, and simulation results
Whalemate processes roster data to run the program. This page declares what is certified today: ISO/IEC 27001:2022. We do not invent SOC 2 or other badges. The DPA is the document that governs processing.
A human-risk program does not work without a roster. That means names, work emails, area, role when it exists, simulation results, and training progress. Those data live to send the exercise, assign reinforcement, and produce evidence. They do not live for a disciplinary file. The Trust Center says what is collected, why, who sees it, and with what retention. The contract and the DPA repeat the use limit. If a customer wants the score for a proceeding, they are asking for something this platform does not offer.
The certification we show is ISO/IEC 27001:2022. The badge is on the site because it is current. We do not list SOC 2, ISO 27701, or other frameworks as ours. Platform controls — encryption in transit and at rest, internal SSO, 2FA, least privilege, access logs, continuity, agreed residency — are described on this page. Residency and subprocessors are closed in the DPA. Infrastructure on AWS. The subprocessor list is updated with notice. Responsible disclosure: security@whalemate.com.
The DPA is the document legal and procurement should ask for, not a marketing paragraph. It defines processing, controller instructions, subprocessors, and retention. The Trust Center does not replace it: it makes it findable. If there is a question the DPA does not cover, it is answered at the security table — not with a new claim on a banner. We want this page to be link-worthy from a tender. That is why we do not fill it with badges we do not have.
Three trust anchors
Certification, data, and permitted use
If one of the three is invented, the Trust Center stops being useful to legal.
ISO/IEC 27001:2022
It is the only certification we declare. The badge visible on the site matches that scope. We do not use the standard as decoration or mix it with your organization’s certification. If a…
What data we process
Name and work email to send and assign. Simulation result for the index and reinforcement. Training progress for evidence. Area and role to calibrate, aggregated when that applies. We do not ask for…
Non-disciplinary use
No individual metric is used to punish. It is in the Trust Center and the contract, not only in a brand value. The program administrator sees the detail. The executive report aggregates. Legal can…
Trust Center questions
Do you have SOC 2 or other certifications besides ISO?
The certification we declare is ISO/IEC 27001:2022. We do not list SOC 2 or other badges as ours. If a tender asks for them, the honest answer is that, plus the DPA and the controls on this page. Inventing an “in process” is not a shortcut we use.
Where do I read the DPA?
In the site’s legal hub, next to privacy, terms, and cookies. The Trust Center links to that document because it governs processing. If you need a negotiated version, that is discussed at the commercial and legal table. This page does not replace signing the DPA.
Can you use our simulation results for marketing?
Public reports do not expose a customer’s roster. A case study is published when the customer and the narrative are validated. We do not use your click rate in an ad. If a research report uses a sample, the method is in that PDF — not in a loose headline.
Who at Whalemate sees the roster?
Internal access follows least privilege and is logged. Customer success sees what is needed to operate the account. It is not open access for the whole team. Subprocessor and residency detail is in the DPA. Ask in the demo if your tender wants a named list.
How do I report a vulnerability?
Write to security@whalemate.com. We respond within 48 business hours. We do not start legal action against good-faith research. There is no bounty program published on this page: if a scope exists, it is communicated on that channel — a prize is not invented here.
Want to review scope with the team?
The Trust Center covers what is certified today. Concrete scope is closed in the demo.
Book a demo