Snapshot 74255
Normalized text
Scripts and page chrome removed; this is what change detection compares.
SecurityPal AI’s Trust Center SecurityPal helps the world’s leading enterprises transform cybersecurity assurance from a business bottleneck into a strategic advantage. Trust and security are foundational to everything we do, from how we build our Cybersecurity Assurance Management Platform (CAMP) to how we protect our customers and partners. We maintain compliance with leading industry standards and global regulations, including SOC 2, GDPR, and CCPA. This Trust Center provides transparent access to information about our security, privacy, compliance, and risk management practices. Request documents Browse 61 controls 3 Certifications 61 Controls 10 Documents <24 hrs RTO and RPO Certifications 3 programs SOC 2 Type 2 Security, availability, and confidentiality. Report available on request. Completed GDPR Processing, transfer, and subject-rights practices aligned to EU requirements. Completed CCPA California consumer privacy rights, disclosures, and data handling. Completed Security controls The practices and safeguards in place across our product, infrastructure and corporate environment. 14 categories · 61 controls Access Control 3 SecurityPal encrypts all data at rest and in transit. SecurityPal implements role-based access control (RBAC) on all data, ensuring that employees only have access to the data they need to perform their jobs. SecurityPal conducts regular data access reviews to ensure that employees only have access to the data they need to perform their jobs. Access is removed for terminated employees within 24 hours SecurityPal has added multiple logging tools to track the company's activity, endpoint, and infrastructure. SecurityPal retains logs for a period of time in accordance with regulatory requirements. SecurityPal generates alerts on changes and events such as log tampering. SecurityPal requires employees to use strong passwords and to change their passwords regularly. SecurityPal implements password lockout policies to prevent brute-force attacks. SecurityPal uses multi-factor authentication (MFA) for remote network access and API access. App Security 5 All codes run through automated testing and static code analysis and receive approval from one or more distinct team members. All updates are required to pass automated testing before they can be deployed to staging and, eventually, production. All infrastructure secrets are stored in GCP Cloud KMS. SecurityPal requires employees to use multi-factor authentication (MFA) when accessing sensitive systems and data. A fully implemented SDLC is in place that includes: Version control Continuous integration Automated lint End-to-end testing Segregation of duties A formal vulnerability and patch management process is in place, including the use of Google Cloud Run and GitHub's Dependabot system to scan for network vulnerabilities, infrastructure, and dependencies. All systems and applications are patched, and high-risk security patches are applied and verified at least monthly on all server platforms. SecurityPal has a firewall setup on GCP that controls the ingress and egress traffic and also manages the workstation traffic via the Global Protect solution provided by the Firewall (Palo Alto firewall). The WAF is monitored 24/7 and updated with new rules as needed. Business Continuity 3 Recovery Time Objective: <24 Hours Recovery Point Objective: <24 Hours Google Cloud Platform, offered by Google, is a suite of products & services that includes application hosting, cloud computing, database services, and more. Corporate Security 6 SecurityPal maintains an inventory of all corporate assets, including hardware, software, and data. SecurityPal has a process for tracking and controlling access to corporate assets. SecurityPal has a process for disposing of corporate assets in a secure manner. SecurityPal has measures in place to safeguard against email-based security threats. SecurityPal uses a variety of email security measures, including spam filtering, content filtering, and malware scanning. SecurityPal employees are trained on how to identify and avoid phishing attacks. SecurityPal has annual security training to enhance staff awareness of security best practices. SecurityPal employees are also trained on specific security controls, such as password management and multi-factor authentication. SecurityPal's human resources processes prioritize security and compliance. ScurityPal has a background check policy in place for all new employees before providing access to company IT systems. SecurityPal has a process for offboarding employees in a secure manner. A well-defined plan is in place for addressing and mitigating security incidents. SecurityPal has regular internal evaluations to identify and address security vulnerabilities. Data Privacy 4 SecurityPal uses Cookies and similar tracking technologies to track the activity on SecurityPal’s Service and stores certain information to improve the service SecurityPal provides. SecurityPal intends to notify customers promptly and ensure that it has as much information as possible to assess the scope of any security breaches accurately. Measures are taken to minimize the impact of the incident by implementing effective containment strategies. All SecurityPal employees must complete security training and acknowledge the employee handbook and code of conduct. Available upon request. Data Security 6 SecurityPal conducts access reviews quarterly on all the applications internally used. Daily backups are conducted. Backups are tested on an annual basis. SecurityPal deletes customers’ data after 30 days of the end of the contract. All data is encrypted at rest using AES-256 at the object and volume level. All data is encrypted in transit using TLS 1.2+. The Google Cloud Platform manages the physical security of our data center Google Physical Security Endpoint Security 3 The workstations used by employees have full-disk encryption for added security. To monitor internet traffic, a network monitoring solution is used. Additionally, solutions are implemented to block any malicious traffic. Trend Micro DR is used as a solution that has endpoints connected to it via the Trend Micro Agent application Installed on all devices. Infrastructure 5 SecurityPal uses GCP for its infrastructure, which provides a number of security features, including: Security groups to control network traffic to and from SecurityPal's resources. IAM (Identity and Access Management) to manage user permissions and access to resources. Robust physical security. SecurityPal relies on GCP which offers Google Cloud Armor against such threats. Google Cloud Armor provides always-on DDoS protection against network or protocol-based volumetric DDoS attacks. This protection is for applications or services behind load balancers. It can detect and mitigate network attacks to allow only well-formed requests through load-balancing proxies. SecurityPal has a BC/DR (Business Continuity/Disaster Recovery) plan to ensure that its business can continue operating in the event of a disaster. The BC/DR plan includes measures to back up data, replicate systems, and failover to alternate sites. SecurityPal has a team of security experts who are responsible for monitoring and protecting its infrastructure. SecurityPal uses a variety of security tools and technologies to protect its infrastructure, including Firewalls Intrusion detection and prevention systems (IDS/IPS) Endpoint protection systems and XDR protection Data encryption vulnerability scanning and patching SecurityPal maintains a separate production environment for its critical systems. This helps to isolate production systems from development and testing environments and reduces the risk of disruption to production systems. Legal 4 SecurityPal’s third-party subprocessor is Google (GCP and Google Workspace) SecurityPal maintains an insurance policy that includes coverage for major security incidents. Terms of Service Privacy Policy Network Security 6 DMARC has been enabled for securitypalhq.com to reduce the risk of spoofing attacks. SecurityPal has a firewall setup on GCP that controls the ingress and egress traffic. To maintain the security of our infrastructure, we have installed a strong Intrusion Detection System that can detect any unauthorized activity. All open web traffic is monitored on the network using network security solutions. At SecurityPal, we ensure the protection of our VPCs through the use of GCP security groups. SecurityPal is accelerating progress toward achieving Zero Trust. Policies 7 Available upon request. Available upon request. Available upon request. Available upon request. Available upon request. Available upon request. Available upon request. Product Security 5 SecurityPal logs activities and data elements to ensure we fulfill our contractual obligations: user id, timestamp, IP address, locale, and event name. Only authorized engineers on a Need To Know basis can access audit logs and activity. SecurityPal has volume, object-level encryption of data at rest. SecurityPal encrypts data in transit. SecurityPal has access controls and permissions around who from SecurityPal has access to certain pieces of data. SecurityPal’s system runs on a third-party cloud provider, and the Google Cloud Platform manages physical controls. For the details on our data center physical security controls, please refer to: GCP Security MFA is deployed and required for access to critical information via the internet and required for all administrators and vendor networks accessing client data. Access approval is based on the role and responsibilities of the user and the principle of least privilege. SecurityPal supports SSO via Google or Microsoft. Reports 3 SecurityPal conducts an annual penetration test with Cobalt. SecurityPal engaged Moss Adams LLP to conduct a SOC 2 Type 1 audit. SecurityPal received an official SOC 2 Type 2 attestation from our independent third-party auditor, Moss Adams LLP. Our auditor examined SecurityPal, Inc. throughout the period from July 1, 2024, to June 30, 2025. Self Assessments 1 Available upon request. Use the request form at the bottom of this assurance profile. Documents These documents are shared under NDA. Select the ones you need — each request goes straight to our security team. 10 available on request Private Business Continuity and Disaster Recovery SecurityPal Business Continuity and Disaster Recovery Plan (2025) Private Certificate of Insurance Certificate of Insurance — Company Liability Private Certificate Of Insurance (Tech E&O) SecurityPal Tech E&O Certificate Of Insurance 2026–2027 Private Cyber Incident Response Plan SecurityPal Cyber Incident Response Plan (2026) Private Data Security Whitepaper SecurityPal Whitepaper (2024) Private Information Security Policy SecurityPal — Information Security Policy (2025) Private SOC 2 Type II SecurityPal AI SOC 2 Type II report Private 2026 SOC 2 Bridge Letter SOC 2 Bridge Letter — SecurityPal 2026 Private SecurityPal Pentest Executive Summary 2026 Penetration testing of the web application conducted Feb 12–26, 2026 by Cobalt Private Data Backup Policy Data Backup (2025) Subprocessors 2 entries Cloud service provider Hosting, storage, and infrastructure for the platform, including physical data-center security. Provider of AI LLMs Optional — engaged only if you choose to use our opt-in AI powered features. Request Information Tell us who you are and which documents you need. We review every request and respond by email. Trust updates 7 Posts September 5, 2025 SOC 2 Type II Compliance Achieved SecurityPal AI, Inc. is proud to announce that we have received an official SOC 2 Type II attestation from our independent third-party auditor, Baker Tilly US LLP. The audit examined our controls and practices from July 1, 2024, to June 30, 2025, assessing the suitability of our control design and the operating effectiveness throughout this period. We’re excited to share that our audit found zero (0) exceptions, reflecting our dedication to maintaining the highest standards of security, availability, and confidentiality. August 28, 2025 SOC 2 Type 2 Compliance Achieved SecurityPal, Inc. is proud to announce that we have received an official SOC 2 Type 2 attestation from our independent third-party auditor, Moss Adams LLP. The audit examined our controls and practices from July 1, 2024, to June 30, 2025, assessing the suitability of our control design and the operating effectiveness throughout this period. We’re excited to share that our audit found zero exceptions, reflecting our dedication to maintaining the highest standards of security, availability, and confidentiality. September 11, 2024 SOC 2 Type 2 Compliance Achieved SecurityPal, Inc. is proud to announce that we have received an official SOC 2 Type 2 attestation from our independent third-party auditor, Moss Adams LLP. The audit examined our controls and practices from July 1, 2023, to June 30, 2024, assessing the suitability of our control design and the operating effectiveness throughout this period. We’re excited to share that our audit found zero exceptions, reflecting our dedication to maintaining the highest standards of security, availability, and confidentiality. September 29, 2023 SOC 2 Type 2 Compliance Achieved SecurityPal received an official SOC 2 Type 2 attestation from our independent third-party auditor, Moss Adams LLP. Our auditor examined SecurityPal, Inc. throughout the period from July 1, 2022 to June 30, 2023. The auditor has also examined the suitability of the design and operating effectiveness of controls stated in the description throughout the period July 1, 2022 to June 30, 2023. September 1, 2023 Introducing the SecurityPal Status Page We are thrilled to introduce the brand-new SecurityPal Status page. This dedicated web page offers real-time updates on the operational status and overall health of the SecurityPal web application. We are enthusiastic about this enhancement and remain steadfast in our commitment to maintaining the robustness, security, and availability of SecurityPal. Go to securitypal.statuspage.io for more information. August 7, 2023 Ongoing SOC 2 Type 2 audit SecurityPal is actively engaged in an ongoing SOC 2 Type 2 audit in collaboration with our independent third-party auditor Moss Adams LLP - www.mossadams.com July 24, 2023 Subprocessor Update: OpenAI SecurityPal is pleased to introduce OpenAI as the latest subprocessor. OpenAI’s services are available as an optional opt-in feature for our customers. We rely on OpenAI to help our customers harness AI (Artificial Intelligence) and LLM (Large Language Model) powered capabilities to instantaneously respond to security, GRC, privacy, and product-related questions and queries. Need Something We Haven't Published Yet? Talk to our security team Stay in the loop Get notified when we publish a new report, add a subprocessor, or post a trust update. No marketing — just changes to this page. Email address You’re subscribed. We’ll email you whenever this trust center changes. We couldn’t subscribe you. Please check your email and try again.Please complete the verification challenge before subscribing.Email is required. Please enter an address to subscribe.That email doesn’t look right. Please check it and try again.We couldn’t reach our servers. Check your connection and try again.Something went wrong on our end. Please try again in a moment.