Transparency

TailoredGRC Trust Center

Security, compliance, and privacy — by design.

TailoredGRC is preparing for first production customer engagements. The security commitments described below reflect the controls, policies, and processes we have implemented as part of our pre-launch readiness program. These commitments will be operationalized and audited as customer engagements begin.

Assurance

Compliance program

TailoredGRC is pre-launch. The status below reflects our readiness program — not completed third-party audits or certifications.

SOC 2 Type II Pre-audit
HIPAA Security Rule Safeguards in place · BAA-ready
NIST CSF 2.0 Aligned
ISO 27001 Planned

SOC 2: TailoredGRC operates a pre-audit compliance program aligned to the SOC 2 Trust Services Criteria. Formal Type II certification is planned ahead of general availability; the audit window will be published once scheduled.

HIPAA: TailoredGRC's security program is structured to support HIPAA compliance for healthcare customers. We have implemented the administrative, physical, and technical safeguards required by the HIPAA Security Rule. Business Associate Agreements will be executed with healthcare customers as customer engagements begin. TailoredGRC is not currently processing PHI; HIPAA compliance posture will be validated in production once we engage healthcare customers.

NIST CSF: TailoredGRC's information security program aligns to the NIST Cybersecurity Framework 2.0 — Govern, Identify, Protect, Detect, Respond, Recover. Maturity tier targets are documented in our internal control library. NIST CSF does not require formal attestation; alignment statements are based on our internal control documentation.

Security

Security posture

Defense in depth across storage, transport, access, and operations.

Encryption at Rest

AES-256 encryption for all stored data.

Encryption in Transit

TLS 1.2+ for all data in transit.

Access Controls

Role-based access control with MFA enforcement.

Session Security

15-minute inactivity timeout aligned to the HIPAA Security Rule.

Vulnerability Management

Vulnerability management process in place; independent penetration testing planned ahead of general availability.

Audit Logging

Access and changes are logged; retention follows our Documentation Retention Standard.

AI

AI governance

Responsible use of AI with customer control and regulatory grounding.

Zero Training Clause

Customer data is never used to train AI models.

Data Isolation

Each customer’s data is completely isolated.

Grounded Responses

AI responses cite specific regulatory sources.

Human Approval Required

All AI recommendations require human review.

What our AI does today

Our AI drafts policies, procedures, and control responses from your workspace data, citing the specific framework requirement behind each recommendation. It runs as single-shot requests under human review — it does not monitor continuously, act on its own, or process PHI.

Underlying AI provider

AI processing is performed by the Anthropic Claude API, configured for zero data retention. Customer data is never used to train AI models.

Read our full AI Governance Disclosure →

Infrastructure

Subprocessors & stack

Key providers that help us deliver the service securely.

Netlify

Hosting, edge functions, CDN · page requests and function execution · US · SOC 2 certified

Supabase

Database, auth, storage · primary customer data · AWS us-east-1 (US)

Anthropic

AI processing (Claude API) · prompts and AI outputs (zero retention configured) · US

Stripe

Payment processing · billing data (PCI-compliant) · US

Cloudflare

CDN, DNS, DDoS protection · page requests · US

Google Workspace

Email (transactional and sales) · customer email addresses and message content · US

GitHub

Source code repository · TailoredGRC internal code (not customer data) · US

Sentry

Error monitoring and application debugging (customer app and admin UI) · error events with user/tenant UUIDs, browser metadata, and stack traces — no PII (IP scrubbing and data scrubbers enabled) · US · SOC 2 Type II certified

No third-party analytics tracking. TailoredGRC does not use Google Analytics, Plausible, PostHog, Mixpanel, or any other third-party analytics or behavioral tracking on our public site or in-product. We measure usage only through our own application logs.

When TailoredGRC engages a new subprocessor that processes customer data, we will notify affected customers at least 30 days in advance through the in-product notification center and via email to designated security contacts.

Data

Data handling

Where your data lives, how long we keep it, and how it is deleted and backed up.

Data Residency

Customer data is stored in the United States only (AWS us-east-1).

Data Retention

Our Documentation Retention Standard defines a 7-year retention period for audit-relevant records.

Data Deletion

Data deletion is available on request to security@tailoredgrc.com; self-service deletion is planned ahead of general availability.

Backups

Database backups managed by Supabase with daily snapshots and 7-day point-in-time recovery.

Resilience

Incident response

How we detect, contain, and communicate security incidents.

Our incident response process follows a defined lifecycle: detection, containment, customer notification, root-cause analysis, and remediation.

If a confirmed security incident affects your data, we will notify you without undue delay.

Our full Incident Response Plan is available to customers and prospects on request.

Legal documents

Review our policies and agreements.

Contact

Trust & security contacts

Reach the right team for security, privacy, and compliance requests.

Security issues

security@tailoredgrc.com

Privacy requests

privacy@tailoredgrc.com