Trust & Security Center

Built for the
Most Demanding Buyers.

Every security control, compliance certification, and SLA commitment — documented in one place. Enterprise procurement teams: this page is for you.

Certification & Compliance Status

Real-time status of every certification. No marketing language — just facts.

⏳ Q3 2026

SOC 2 Type 2

Independent audit of security, availability, and confidentiality controls. Audit period began Q1 2026. Report expected Q3 2026.

✓ Active

GDPR Compliant

Full compliance with EU General Data Protection Regulation. Data processing agreements available on request.

✓ Active

CCPA Compliant

California Consumer Privacy Act compliance. Users can request data export or deletion at any time.

⏳ Q2 2026

HIPAA Ready

Business Associate Agreements (BAA) available for healthcare clients on Enterprise tier. Full HIPAA controls in implementation.

✓ Active

End-to-End Encryption

All data encrypted in transit (TLS 1.3) and at rest (AES-256). Encryption keys managed via industry-standard KMS.

⏳ Q2 2026

SSO / SAML 2.0

Single Sign-On via Okta, Azure AD, Google Workspace, and any SAML 2.0 provider. Available on Enterprise tier Q2 2026.

Security Controls

Technical controls in place today, verified continuously.

TLS 1.3 Encryption

All data in transit encrypted with TLS 1.3. No unencrypted channels.

AES-256 at Rest

All stored data encrypted with AES-256. Keys rotated quarterly.

Role-Based Access Control

Granular RBAC with Owner, Manager, Editor, and Viewer roles.

Audit Logs

Immutable logs of every user action, API call, and data change. Retained 12 months.

Automated Backups

Database backups every 6 hours. Point-in-time recovery up to 30 days.

Vulnerability Management

Continuous dependency scanning. Critical patches deployed within 24 hours.

Global CDN

Content delivered via global CDN with DDoS protection and WAF.

Penetration Testing

Annual third-party penetration tests. Results available to Enterprise customers under NDA.

Service Level Agreements

Contractual uptime guarantees and support response times by tier.

PlanUptime SLASupport ResponseIncident Notification
Starter99.5%Email (48h)Status page
Growth99.9%Email (24h)Email notification
Agency99.9%Priority (8h)Email + SMS
Enterprise99.95%Dedicated (4h)Direct contact + SLA credits

SLA credits issued for downtime exceeding guaranteed thresholds. Enterprise SLA available as addendum to MSA.

Single Sign-On (SSO)

Enterprise SSO via SAML 2.0 and OIDC is available on the Enterprise tier. Connect your existing identity provider — Okta, Azure Active Directory, Google Workspace, or any SAML 2.0 compliant IdP.

Okta
Azure AD
Google Workspace
Any SAML 2.0

HIPAA Compliance for Healthcare

Medical practices, dental offices, and healthcare providers require HIPAA-compliant marketing tools. ScaleDesk360™ Enterprise includes a Business Associate Agreement (BAA) and HIPAA-specific data handling controls.

Business Associate Agreement

Signed BAA included with Enterprise tier for all healthcare clients.

PHI Data Isolation

Patient-adjacent data stored in isolated, encrypted partitions.

Audit Trail

Full immutable audit log of all access to healthcare client data.

Security Questions?

Our security team responds to enterprise inquiries within 4 business hours.