Snapshot 40825
Normalized text
Scripts and page chrome removed; this is what change detection compares.
NewsWhalemate is ISO/IEC 27001:2022 certifiedSee Trust Center How we protect your organization's data Whalemate processes names, emails and simulation results of your employees. Where that data lives, who accesses it and under which controls. We only show what is certified today: ISO/IEC 27001:2022. See the DPA Architecture Platform controls Encryption TLS 1.3 in transit and AES-256 at rest. Access SSO for the internal team, 2FA and least privilege. Traceability Access and change logging. Continuity Availability and recovery controls. Residency Hosting according to the scope agreed with the customer. Retention Retention and deletion policy defined in the DPA. Employee data What we collect and why No individual metric is used for disciplinary purposes. That's in the contract, not only on this page. Data Why Who sees it Retention Name and work email Send the simulation and assign training Program administrator For the life of the contract Simulation result Compute the index and trigger reinforcement Program administrator 24 months Training progress Compliance evidence Administrator and audit 24 months Area and role Calibrate the scenario by profile Aggregated, not individual For the life of the contract Responsible disclosure Subprocessors If you found a vulnerability, write to security@whalemate.com. We respond within 48 business hours. We do not take legal action against good-faith research. Infrastructure on AWS. Transactional email and product analytics per the current DPA. The full list is updated with prior notice. security@whalemate.com In this module Program capabilities Access 2FA, session and brute-force Whoever administers does not get in on a password alone. 2FA, session time, and brute-force lockout sit in the console, next to roles and the audit log. Permissions Users, roles and permissions Who enters the console. Not roster SSO: operator access, with least privilege. Trails Audit log Admin changes: who touched a permission, when. Course-completion logs also live on compliance. Trust Center How we handle names, emails, and simulation results Whalemate processes roster data to run the program. This page declares what is certified today: ISO/IEC 27001:2022. We do not invent SOC 2 or other badges. The DPA is the document that governs processing. A human-risk program does not work without a roster. That means names, work emails, area, role when it exists, simulation results, and training progress. Those data live to send the exercise, assign reinforcement, and produce evidence. They do not live for a disciplinary file. The Trust Center says what is collected, why, who sees it, and with what retention. The contract and the DPA repeat the use limit. If a customer wants the score for a proceeding, they are asking for something this platform does not offer. The certification we show is ISO/IEC 27001:2022. The badge is on the site because it is current. We do not list SOC 2, ISO 27701, or other frameworks as ours. Platform controls — encryption in transit and at rest, internal SSO, 2FA, least privilege, access logs, continuity, agreed residency — are described on this page. Residency and subprocessors are closed in the DPA. Infrastructure on AWS. The subprocessor list is updated with notice. Responsible disclosure: security@whalemate.com. The DPA is the document legal and procurement should ask for, not a marketing paragraph. It defines processing, controller instructions, subprocessors, and retention. The Trust Center does not replace it: it makes it findable. If there is a question the DPA does not cover, it is answered at the security table — not with a new claim on a banner. We want this page to be link-worthy from a tender. That is why we do not fill it with badges we do not have. Three trust anchors Certification, data, and permitted use If one of the three is invented, the Trust Center stops being useful to legal. ISO/IEC 27001:2022 It is the only certification we declare. The badge visible on the site matches that scope. We do not use the standard as decoration or mix it with your organization’s certification. If a… What data we process Name and work email to send and assign. Simulation result for the index and reinforcement. Training progress for evidence. Area and role to calibrate, aggregated when that applies. We do not ask for… Non-disciplinary use No individual metric is used to punish. It is in the Trust Center and the contract, not only in a brand value. The program administrator sees the detail. The executive report aggregates. Legal can… Trust Center questions Do you have SOC 2 or other certifications besides ISO? The certification we declare is ISO/IEC 27001:2022. We do not list SOC 2 or other badges as ours. If a tender asks for them, the honest answer is that, plus the DPA and the controls on this page. Inventing an “in process” is not a shortcut we use. Where do I read the DPA? In the site’s legal hub, next to privacy, terms, and cookies. The Trust Center links to that document because it governs processing. If you need a negotiated version, that is discussed at the commercial and legal table. This page does not replace signing the DPA. Can you use our simulation results for marketing? Public reports do not expose a customer’s roster. A case study is published when the customer and the narrative are validated. We do not use your click rate in an ad. If a research report uses a sample, the method is in that PDF — not in a loose headline. Who at Whalemate sees the roster? Internal access follows least privilege and is logged. Customer success sees what is needed to operate the account. It is not open access for the whole team. Subprocessor and residency detail is in the DPA. Ask in the demo if your tender wants a named list. How do I report a vulnerability? Write to security@whalemate.com. We respond within 48 business hours. We do not start legal action against good-faith research. There is no bounty program published on this page: if a scope exists, it is communicated on that channel — a prize is not invented here. Want to review scope with the team? The Trust Center covers what is certified today. Concrete scope is closed in the demo. Book a demo