Frequently Asked Questions
Do you encrypt data at rest?
Yes. All customer data is encrypted at rest using AES-256 encryption.
Do you encrypt data in transit?
Yes. All data in transit is encrypted using TLS 1.2 or higher.
Do you support SSO / SAML?
Yes. We support SAML 2.0 SSO integration with major identity providers.
Do you enforce multi-factor authentication?
Yes. MFA is enforced for all employee access to production systems.
Where is customer data stored?
All customer data is stored in [REGION]. Contact us for data residency documentation.
Do you perform regular penetration testing?
Yes. We conduct annual third-party penetration testing and address all findings.
Do you have a vulnerability disclosure program?
Yes. See our vulnerability disclosure page for responsible reporting guidelines.
What is your incident response process?
We maintain a documented incident response plan with defined notification timelines.
Can customers request data deletion?
Yes. We honor all data deletion requests within 30 days per applicable regulations.
Do you have a Data Processing Agreement (DPA)?
Yes. We provide a DPA to all customers upon request.
Can we review your SOC 2 report?
Yes. SOC 2 Type II reports are available under NDA. Contact security@yourcompany.com.