Snapshot 64620
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Trust Center Start your security review View & download sensitive information Ask for information Overview Welcome to the Ordergroove Trust Center. Ordergroove provides a Relationship Commerce Cloud, and this portal is designed to give you a clear understanding of our commitment to security and trust. Here, you'll find comprehensive information about the security and privacy practices we have in place to protect our systems and your data. Our trust posture is built upon a foundation of rigorous controls and oversight. We regularly undergo independent examinations, such as the SOC 2® Report, which assesses our system's controls against the Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy. This report provides assurance that our service commitments and system requirements are met. Ordergroove maintains a strong governance structure, with our Board of Directors demonstrating independence from management and actively overseeing the development and performance of internal controls, including security and privacy risks. We also emphasize integrity and ethical values, with clear policies, a code of conduct, and a disciplinary process for any violations. Data protection is paramount. We have established a clear point of contact for privacy inquiries, allowing data subjects to submit requests or report incidents. Furthermore, we meticulously manage our relationships with third-party service providers and vendors, ensuring they meet our stringent requirements for preserving and protecting information through due diligence, risk assessments, and formal contracts that address security and privacy. While we utilize subservice organizations for cloud hosting, we ensure that complementary controls are in place to achieve our service commitments. To further mitigate risks, Ordergroove maintains cybersecurity insurance to address the financial impact of potential security incidents. This Trust Center provides detailed evidence of these practices, offering transparency into how Ordergroove safeguards its systems and your information. Compliance PCI DSS v4.0.1 SOC 2 Type 1 Documents COMPLIANCEPCI DSS v4.0.1 COMPLIANCESOC 2 Type 1 Risk Profile We have secure, reliable hosting that customers can depend on. We are happy to provide details about our risk mitigation practices and recovery objectives upon request. Product Security Audit Logging Data Security Integrations View more Reports We may provide security-related reports upon request. Self-Assessments We are working on our security compliance. We can provide completed questionnaires upon request. Data Security Access Monitoring Certificates of Destruction Data Asset Classification View more App Security Responsible Disclosure Application Penetration Testing Code Analysis View more AI We take the usage of AI seriously in our organization and work to ensure security and reliability of the AI. ESG We prioritize and take environmental, social, and governance (ESG) considerations seriously in our operations and decision-making processes. Legal We take legal matters seriously and we always engage our legal counsel to review all commercial activities. Please contact us if you have any questions. Data Privacy Data Breach Notifications Data Into System Data Privacy Officer View more Access Control Access Log Management Automated Account Management Bring Your Own Device (BYOD) View more Infrastructure BC/DR Data Center Environment Segregation View more Endpoint Security Anti-Malware Disk Encryption Endpoint Detection & Response View more Network Security Bot Detection Data Loss Prevention Distributed Denial of Service Protection (Anti-DDoS) View more Corporate Security Employee Training HR Security Incident Response View more Policies Acceptable Use Policy Access Control Policy Anti-Malicious Software Policy View more Security Grades We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available. Incident Response Designated Response Personnel Incident Reporting Process Risk Management Data Access/Impact Levels Risk Assessments Supply Chain Risk Management View more Asset Management Asset Classification Asset Inventories (Hardware/Software) Asset Tracking View more BC/DR Business Continuity Plan (BCP) Data Backup/Backup Protection Disaster Recovery Plan (DRP) Training Employee Privacy Training Phishing Training Role-Based Training View more Change Management Change Advisory Board (CAB) Change Control Board (CCB) Change Management Program View more Physical & Environment Alarms & Surveillance Alternate Work Sites Facility Component Security View more Continuous Monitoring Data Loss Prevention System (DLP) Event & Audit Log Management File Integrity Monitoring (FIM) View more