Access and data protection
Customer data is encrypted in transit and at rest. Production access is limited to named operators using MFA.
Review data protectionTrust Center
Review how TestifySec protects customer data, manages security, and supports your vendor assessment.
Last reviewed: October 6, 2026
Compliance status
Our examination is in progress for the Security, Availability, and Confidentiality Trust Services Criteria.
Review the program scopeIn progress
TestifySec does not yet hold a SOC 2 auditor’s opinion. A SOC 2 report is not currently available.
Security practices
Read the overview or request supporting policies for your security review.
Customer data is encrypted in transit and at rest. Production access is limited to named operators using MFA.
Review data protectionWe log platform activity, back up production data, and test database restoration. Review the current recovery scope and limitations.
Review recovery practicesHuman approval for major releases, automated review, and vulnerability management support our development process.
Review development practicesData handling
For the hosted Platform, TestifySec operates the service infrastructure. For a customer-managed appliance, you operate the infrastructure. Data handling and support arrangements depend on your deployment and customer agreement.
Discuss your data requirementsRequest the current Platform subprocessor list for your review. Change notices follow the terms of your customer agreement.
Request the subprocessor listSecurity review
Encryption, access, logging, recovery testing, and the current assurance program.
Read security practicesRequest the current list of service providers that process Platform customer data.
Request the subprocessor listHow information collected through our website is used and handled.
Read the privacy policyRequest the policy package, current control mapping, and subprocessor list for your review.
Request documents by emailResponsible disclosure
Send it to our security team using the private reporting channels.