Skip to main content

Trust Center

Security and
compliance.

Review how TestifySec protects customer data, manages security, and supports your vendor assessment.

Last reviewed: October 6, 2026

Compliance status

SOC 2 Type I

Our examination is in progress for the Security, Availability, and Confidentiality Trust Services Criteria.

Review the program scope

In progress

TestifySec does not yet hold a SOC 2 auditor’s opinion. A SOC 2 report is not currently available.

Security practices

How we protect customer data.

Read the overview or request supporting policies for your security review.

Access and data protection

Customer data is encrypted in transit and at rest. Production access is limited to named operators using MFA.

Review data protection

Operations and recovery

We log platform activity, back up production data, and test database restoration. Review the current recovery scope and limitations.

Review recovery practices

Secure development

Human approval for major releases, automated review, and vulnerability management support our development process.

Review development practices

Data handling

Privacy and subprocessors

Customer data

For the hosted Platform, TestifySec operates the service infrastructure. For a customer-managed appliance, you operate the infrastructure. Data handling and support arrangements depend on your deployment and customer agreement.

Discuss your data requirements

Service providers

Request the current Platform subprocessor list for your review. Change notices follow the terms of your customer agreement.

Request the subprocessor list

Security review

Documents for your assessment.

Responsible disclosure

Found a security issue?

Send it to our security team using the private reporting channels.