Third Party Index

Snapshot 64620

Document
Trust center
URL
https://trust.ordergroove.com/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
404376 bytes
SHA-256 (raw)
6c598b2770ab84e6fc0d943f04753e1e5160c2313195c75bf4826cb2521fc931
SHA-256 (normalized text)
60fca0ac4bb2b6c9bcab3340fd0b6a399aa77ec351ea953f9d37a09cfaeada83

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust Center
Start your security review
View & download sensitive information
Ask for information
Overview
Welcome to the Ordergroove Trust Center. Ordergroove provides a Relationship Commerce Cloud, and this portal is designed to give you a clear understanding of our commitment to security and trust.
Here, you'll find comprehensive information about the security and privacy practices we have in place to protect our systems and your data. Our trust posture is built upon a foundation of rigorous controls and oversight. We regularly undergo independent examinations, such as the SOC 2® Report, which assesses our system's controls against the Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy. This report provides assurance that our service commitments and system requirements are met.
Ordergroove maintains a strong governance structure, with our Board of Directors demonstrating independence from management and actively overseeing the development and performance of internal controls, including security and privacy risks. We also emphasize integrity and ethical values, with clear policies, a code of conduct, and a disciplinary process for any violations.
Data protection is paramount. We have established a clear point of contact for privacy inquiries, allowing data subjects to submit requests or report incidents. Furthermore, we meticulously manage our relationships with third-party service providers and vendors, ensuring they meet our stringent requirements for preserving and protecting information through due diligence, risk assessments, and formal contracts that address security and privacy. While we utilize subservice organizations for cloud hosting, we ensure that complementary controls are in place to achieve our service commitments. To further mitigate risks, Ordergroove maintains cybersecurity insurance to address the financial impact of potential security incidents.
This Trust Center provides detailed evidence of these practices, offering transparency into how Ordergroove safeguards its systems and your information.
Compliance
PCI DSS v4.0.1
SOC 2 Type 1
Documents
COMPLIANCEPCI DSS v4.0.1
COMPLIANCESOC 2 Type 1
Risk Profile
We have secure, reliable hosting that customers can depend on. We are happy to provide details about our risk mitigation practices and recovery objectives upon request.
Product Security
Audit Logging
Data Security
Integrations
View more
Reports
We may provide security-related reports upon request.
Self-Assessments
We are working on our security compliance. We can provide completed questionnaires upon request.
Data Security
Access Monitoring
Certificates of Destruction
Data Asset Classification
View more
App Security
Responsible Disclosure
Application Penetration Testing
Code Analysis
View more
AI
We take the usage of AI seriously in our organization and work to ensure security and reliability of the AI.
ESG
We prioritize and take environmental, social, and governance (ESG) considerations seriously in our operations and decision-making processes.
Legal
We take legal matters seriously and we always engage our legal counsel to review all commercial activities. Please contact us if you have any questions.
Data Privacy
Data Breach Notifications
Data Into System
Data Privacy Officer
View more
Access Control
Access Log Management
Automated Account Management
Bring Your Own Device (BYOD)
View more
Infrastructure
BC/DR
Data Center
Environment Segregation
View more
Endpoint Security
Anti-Malware
Disk Encryption
Endpoint Detection & Response
View more
Network Security
Bot Detection
Data Loss Prevention
Distributed Denial of Service Protection (Anti-DDoS)
View more
Corporate Security
Employee Training
HR Security
Incident Response
View more
Policies
Acceptable Use Policy
Access Control Policy
Anti-Malicious Software Policy
View more
Security Grades
We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.
Incident Response
Designated Response Personnel
Incident Reporting Process
Risk Management
Data Access/Impact Levels
Risk Assessments
Supply Chain Risk Management
View more
Asset Management
Asset Classification
Asset Inventories (Hardware/Software)
Asset Tracking
View more
BC/DR
Business Continuity Plan (BCP)
Data Backup/Backup Protection
Disaster Recovery Plan (DRP)
Training
Employee Privacy Training
Phishing Training
Role-Based Training
View more
Change Management
Change Advisory Board (CAB)
Change Control Board (CCB)
Change Management Program
View more
Physical & Environment
Alarms & Surveillance
Alternate Work Sites
Facility Component Security
View more
Continuous Monitoring
Data Loss Prevention System (DLP)
Event & Audit Log Management
File Integrity Monitoring (FIM)
View more