Trust Center

We secure security teams. Here's how we secure ours.

The bar for this category is high, and our documentation should clear it. Here's how we handle your data, who can touch it, and what you can review under NDA.

Active
SOC 2 Type II Audited
U.S.-based SOC 100% U.S. soil
Hosting U.S. regions
Encryption in transit TLS 1.3
Tenant isolation Logical
Audits & attestations

Audits & Attestations

We commission third-party audits every year and hold our own operation to the same control standards we deliver to customers. In this category, that isn't a differentiator. It's the minimum.

Audited & Attested
SOC 2
Active

SOC 2 Type II

Security, Availability, and Confidentiality. Twelve-month observation window. Audited annually by an independent CPA firm.

Latest report: April 1, 2025
Available under NDA
HIPAA
Aligned

HIPAA Security Rule

Administrative, physical, and technical safeguards mapped. Standing BAA template available for healthcare customers.

BAA: standing template
Mapping: 45 CFR §164
On our roadmap
CMMC
Roadmap

CMMC Level 2

Working toward CMMC Level 2 (NIST SP 800-171 Rev 2). Certification requires a third-party (C3PAO) assessment, which we are actively working toward.

Status: roadmap
C3PAO assessment: planned
ISO 27001
Roadmap

ISO/IEC 27001:2022

Targeted for a future assessment cycle. Annex A controls are being mapped as part of our certification roadmap.

Target: future assessment cycle
Status: roadmap
Data handling

Where your data lives and who can touch it.

DATA RESIDENCY

U.S.-based hosting.

The ArmorPoint agent transmits customer telemetry directly to our U.S. infrastructure in Phoenix. Primary tenant infrastructure operates in U.S. regions.

Primary hosting
ArmorPoint U.S. data center
Cloud workloads
U.S. regions
ENCRYPTION

TLS 1.3 in transit.

Traffic to and within the platform is encrypted in transit with TLS 1.3.

In transit
TLS 1.3 minimum
SOC ACCESS MODEL

U.S.-based. Background-checked.

All Tier 1, Tier 2, and incident-response analysts are U.S.-based personnel operating on U.S. soil; ArmorPoint does not offshore its SOC or incident-response work. Access to customer environments requires MFA and is logged and monitored.

Access controls
Background checksRequired
MFARequired
Session loggingEnabled
DATA RETENTION

Policy-driven. Customer-controlled.

Telemetry retention defaults to 12 months (extendable per contract). Evidence and audit artifacts retain per regulatory requirement. On termination, customer data export and certified deletion are handled per your executed agreement.

Default retention
12 months
Post-termination
Per agreement
How we operate

The discipline behind the platform.

Vulnerability management

Continuous vulnerability scanning across our environment. Independent third-party penetration testing conducted annually. Risk-based remediation per our vulnerability management policy.

Remediation: critical 2d · high 1wk · medium 30d · low 90d

Patch & configuration management

Infrastructure managed as code. Defined patch and configuration management process. Remediation applied with your approval.

Critical patches: within 30 days

Incident response (our own)

24/7 incident-response coverage. Documented incident-response playbooks. Same-business-day notification target for confirmed incidents affecting customer data; specific terms per your executed agreement.

Notification: service-level target

Business continuity & DR

Failover and tabletop exercises are conducted regularly to validate business continuity and disaster recovery.

Failover test: annual · Tabletops: 2× per year

Personnel security

Background checks at hire. Mandatory annual security-awareness training. Role-based access reviews conducted periodically.

Security training: annual
Available under NDA

Documents your security team can request.

Review documents are available to qualified prospects and customers under a mutual NDA. Request them through your partner contact or your ArmorPoint account team. Typical turnaround is 2 business days.

AvailablePDF · NDA

SOC 2 Type II Report

Most-recent issued SOC 2 Type II report covering Security, Availability, and Confidentiality. Includes management response.

~120 pages
AvailableDOCX

BAA template (HIPAA)

Standing Business Associate Agreement template, ready for execution.

Editable
AvailableXLSX

Security questionnaire (CAIQ-style)

We complete security questionnaires (SIG, VSA, and CAIQ-style) on request.

~250 controls
Still got questions?

Bring your procurement-team checklist.

We'll bring our governance lead to the demo if it helps. The fastest way through a security review is to get your questions and the people who can answer them in the same room.

Security & vulnerability disclosure
[email protected]
System status
status.armorpoint.com

Information current as of 6/30/2026; subject to change. The controlling terms are those in your executed agreement.