Encrata Trust Center
This is our Trust Center, covering how we approach data security and compliance, the certifications we hold, the controls we operate, and direct answers to the questions we hear most from security teams.
How we think about security
A few commitments that shape how we build, ship, and operate. They show up in our architecture, our policies, and how our team works day to day.
Compliance
Independent audits are how we hold ourselves accountable. The frameworks below cover information security, AI management, and the data protection laws our customers operate under.
Resources
The documentation behind our practices. Most reports are released under a mutual NDA. Our security team responds within two business days.
ISO 27001 Certificate
Our certificate of registration, along with the Statement of Applicability.
RequestSOC 2 Reports
Independent attestation reports on the design and operating effectiveness of our controls. Shared under mutual NDA.
RequestPenetration Test Summary
Executive summary of our most recent third-party web application and API penetration test.
RequestInformation Security Policy
Our top-level policy and the ISMS control set that governs security, availability, and confidentiality.
RequestData Processing Addendum
Our standard DPA covering Encrata's role as a processor under GDPR, DPDP, and equivalent regimes.
VisitAcceptable Use Policy
The rules that govern how our platform and APIs may be used.
VisitRefund Policy
How prepaid credits, refunds, downtime compensation, and consumer withdrawal rights work.
VisitSubprocessors
The full, current list of data subprocessors we rely on to deliver the service.
VisitPrivacy Policy
How we collect, process, and retain data across our products and APIs.
VisitIncident Response Plan
How we detect, contain, and notify. Includes our notification commitment and the lessons-learned step after every incident.
RequestControls
A summary view of the technical and organisational controls we operate every day, across security, privacy, and AI safety.




