Third Party Index

Snapshot 43666

Document
Trust center
URL
https://www.firsttouch.com/trust
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
82733 bytes
SHA-256 (raw)
c8d9432f147a1ceb1038ad1d4d46d098e6b4b0111aafa3dbbde731c1eb4cef4b
SHA-256 (normalized text)
f5bbf76b9f0e1096bc7ae1d94a28af95a2b8fc01afde5cd0801cfdc333c276a2

Normalized text

Scripts and page chrome removed; this is what change detection compares.

First Touch Trust Center.
How we protect customer data at FirstTouch. For security questionnaires, reports under NDA, or a copy of our Data Processing Addendum, email [email protected].
Independent assurance
SOC 2 Type II
Covers the Security trust services criteria. The report is available to customers and prospects under NDA.
Report under NDA
CASA Tier 2
Our application has been assessed against the OWASP Application Security Verification Standard through the App Defense Alliance.
Assessed May 2026
Penetration testing
An independent test of the platform at least annually. Findings are triaged and remediated on defined timelines.
Summary under NDA
Commitments we hold ourselves to
48 hoursMaximum time to notify affected customers of a personal data breach, per our DPA
30 daysCustomer data deleted from active systems after termination, with written certification on request
6 monthsMaximum retention for encrypted backups, which expire on a defined schedule
NeverCustomer data used to train AI models, by us or by our AI subprocessors
How the platform is protected
1Infrastructure and hosting
The platform runs on Amazon Web Services in the United States. Production systems are protected by layered network controls and are logically isolated from corporate systems. Customer data is never stored on employee workstations or local servers.
2Encryption
Customer data is encrypted in transit using TLS and encrypted at rest across production databases, storage, and backups.
3Access control
Access to production systems and customer data is limited by role and business need. Multi-factor authentication is enforced for privileged and production systems, access is reviewed periodically, and access is revoked promptly when personnel change roles or leave.
4Secure development
Production and non-production environments are segregated. Changes to production go through code review and testing before deployment, and emergency changes receive post-implementation review.
5Monitoring and vulnerabilities
Security logs are generated and retained for production systems. Threat detection and vulnerability management processes identify material issues, and identified high-risk issues are tracked to remediation.
6Backups and continuity
Backups are encrypted and protected by access controls. Disaster recovery and data restoration procedures are maintained and tested periodically.
How your data is handled
7Retention and deletion
Customers can delete their data or request deletion at any time. On termination, customer data is deleted from active systems within 30 days, with written certification of deletion available on request. Encrypted backups expire on a defined schedule with a maximum retention of six months.
8Subprocessors
A current list of the subprocessors that may process customer data is available at docs.firsttouch.com/approved-subprocessors. We provide notice of material changes as described in our Data Processing Addendum.
9AI and customer data
AI features are optional and can be disabled at the workspace level. Our Data Processing Addendum prohibits AI subprocessors from using customer data to train, fine-tune, or otherwise improve their models, and FirstTouch does not use customer data to train AI models.
10Breach notification
Our Data Processing Addendum commits us to notifying affected customers of a personal data breach without undue delay, and in any event within 48 hours of becoming aware of it. Customers receive a named security contact and a direct escalation path.
11Data Processing Addendum
Our standard DPA covers processor obligations, subprocessor management, international transfers under the EU Standard Contractual Clauses and the UK Addendum, and audit rights. Request a copy at [email protected].
Found a vulnerability?
If you believe you have found a security vulnerability in a FirstTouch product, report it to [email protected] and we will investigate promptly.
Security reviews and privacy requests
Security questionnaires, reports under NDA, and privacy requests go to [email protected].
Our Terms of Service and Privacy Policy are available on this site.
We use cookies to give you the best online experience. Find out more in our cookie policy.
Preferences
Deny
Accept all