Encryption at Rest
AES-256 encryption for all stored data.
Transparency
Security, compliance, and privacy — by design.
TailoredGRC is preparing for first production customer engagements. The security commitments described below reflect the controls, policies, and processes we have implemented as part of our pre-launch readiness program. These commitments will be operationalized and audited as customer engagements begin.
Assurance
TailoredGRC is pre-launch. The status below reflects our readiness program — not completed third-party audits or certifications.
SOC 2: TailoredGRC operates a pre-audit compliance program aligned to the SOC 2 Trust Services Criteria. Formal Type II certification is planned ahead of general availability; the audit window will be published once scheduled.
HIPAA: TailoredGRC's security program is structured to support HIPAA compliance for healthcare customers. We have implemented the administrative, physical, and technical safeguards required by the HIPAA Security Rule. Business Associate Agreements will be executed with healthcare customers as customer engagements begin. TailoredGRC is not currently processing PHI; HIPAA compliance posture will be validated in production once we engage healthcare customers.
NIST CSF: TailoredGRC's information security program aligns to the NIST Cybersecurity Framework 2.0 — Govern, Identify, Protect, Detect, Respond, Recover. Maturity tier targets are documented in our internal control library. NIST CSF does not require formal attestation; alignment statements are based on our internal control documentation.
Security
Defense in depth across storage, transport, access, and operations.
AES-256 encryption for all stored data.
TLS 1.2+ for all data in transit.
Role-based access control with MFA enforcement.
15-minute inactivity timeout aligned to the HIPAA Security Rule.
Vulnerability management process in place; independent penetration testing planned ahead of general availability.
Access and changes are logged; retention follows our Documentation Retention Standard.
AI
Responsible use of AI with customer control and regulatory grounding.
Customer data is never used to train AI models.
Each customer’s data is completely isolated.
AI responses cite specific regulatory sources.
All AI recommendations require human review.
Our AI drafts policies, procedures, and control responses from your workspace data, citing the specific framework requirement behind each recommendation. It runs as single-shot requests under human review — it does not monitor continuously, act on its own, or process PHI.
AI processing is performed by the Anthropic Claude API, configured for zero data retention. Customer data is never used to train AI models.
Infrastructure
Key providers that help us deliver the service securely.
Hosting, edge functions, CDN · page requests and function execution · US · SOC 2 certified
Database, auth, storage · primary customer data · AWS us-east-1 (US)
AI processing (Claude API) · prompts and AI outputs (zero retention configured) · US
Payment processing · billing data (PCI-compliant) · US
CDN, DNS, DDoS protection · page requests · US
Email (transactional and sales) · customer email addresses and message content · US
Source code repository · TailoredGRC internal code (not customer data) · US
Error monitoring and application debugging (customer app and admin UI) · error events with user/tenant UUIDs, browser metadata, and stack traces — no PII (IP scrubbing and data scrubbers enabled) · US · SOC 2 Type II certified
No third-party analytics tracking. TailoredGRC does not use Google Analytics, Plausible, PostHog, Mixpanel, or any other third-party analytics or behavioral tracking on our public site or in-product. We measure usage only through our own application logs.
When TailoredGRC engages a new subprocessor that processes customer data, we will notify affected customers at least 30 days in advance through the in-product notification center and via email to designated security contacts.
Data
Where your data lives, how long we keep it, and how it is deleted and backed up.
Customer data is stored in the United States only (AWS us-east-1).
Our Documentation Retention Standard defines a 7-year retention period for audit-relevant records.
Data deletion is available on request to security@tailoredgrc.com; self-service deletion is planned ahead of general availability.
Database backups managed by Supabase with daily snapshots and 7-day point-in-time recovery.
Resilience
How we detect, contain, and communicate security incidents.
Our incident response process follows a defined lifecycle: detection, containment, customer notification, root-cause analysis, and remediation.
If a confirmed security incident affects your data, we will notify you without undue delay.
Our full Incident Response Plan is available to customers and prospects on request.
Legal
Review our policies and agreements.
How we collect, use, and protect information.
ViewTerms governing use of the platform.
ViewOur commitment to ethical, trafficking-free operations.
ViewBinding contract provided during customer contracting — request access.
Request accessBinding contract provided during customer contracting — request access.
Request accessContact
Reach the right team for security, privacy, and compliance requests.