Trust Center
01Certifications and attestations
Independent assurance is the part of a trust posture that cannot be self-asserted, so it is listed separately from the controls below and with its evidence named.
Customers and prospects under NDA can request current reports and certificates at [email protected].
| Standard | Status | Scope |
|---|---|---|
| SOC 2 Type II | Compliant — [auditor, audit period, report date] | Security, availability and confidentiality |
| ISO/IEC 27001 | Compliant — [certificate number and certification body] | Information security management |
| DPDPA / GDPR | Aligned | India, EU and UK personal data protection |
| HIPAA | Ready | US protected health information |
| CERT-In empanelment | [empanelled? empanelment reference] | India incident reporting and audit |
02How we protect customer data
Role-based access control with granular permissions, on a least-privilege model. Access reviewed every [review cadence].
Multi-factor authentication supporting TOTP, SMS and hardware tokens.
AES-256 at rest and TLS 1.3 in transit.
Our own SOC monitors the products we operate, on the same 24/7 basis we sell to customers.
Continuous scanning plus independent penetration testing [pen-test cadence and last test date].
Backups taken [backup frequency], with a recovery objective of [RTO / RPO].
Background checks where lawful, confidentiality agreements, and security training at onboarding and annually.
Peer review, dependency scanning and separated build, staging and production environments.
A documented plan with defined severities and notification timelines. Vulnerability reports are acknowledged within 24 hours and critical issues resolved within 48 — see the Security page.
Monthly security bulletins covering threats, patches and recommendations.
03Where data lives
Hosting region is a contractual choice, not a default, because data residency is the first question in regulated Indian and Gulf deals.
- Primary hosting: [cloud provider and regions]
- Data residency options: [which regions can be pinned]
- Cross-border transfers: governed by the mechanisms described in the Privacy Policy
- Full list of third parties that may process customer data: Sub-processors
04Product coverage
The three products in the Purplecop One ecosystem are covered by the controls above. Each is sold and deployed on its own, and each inherits the same identity, control library and evidence store.
See all three products
05Documents
- Privacy Policy — what we collect, why, and the rights you hold
- Terms of Service — the terms the products are provided under
- Security & Responsible Disclosure — how to report a vulnerability
- Cookie Policy — what this website stores in your browser
- Sub-processors — third parties that may process customer data
