Encrata Trust Center

This is our Trust Center, covering how we approach data security and compliance, the certifications we hold, the controls we operate, and direct answers to the questions we hear most from security teams.

How we think about security

A few commitments that shape how we build, ship, and operate. They show up in our architecture, our policies, and how our team works day to day.

01 / Posture

Secure by default.

Every design decision starts from the conservative position. Least-privilege access, encryption at rest and in transit, tenant isolation, and ephemeral storage are defaults, not toggles you have to opt into.

02 / Deployment

Built for high-stakes environments.

Multiple deployment models for different security needs: managed SaaS, single-tenant, or fully isolated with zero external network dependency. We run them in production for security teams, fintech, and critical infrastructure.

03 / Data stewardship

Your data stays yours.

Customer Managed Keys for Enterprise ensure that even we cannot see your data at rest. We don't share data across tenants, and we never move it across borders unless you ask us to.

04 / Transparency

Honest about where we are.

We publish the certifications we hold and the ones still in progress. We won't claim a control we don't run, and we'll update this page as our program matures.

Compliance

Independent audits are how we hold ourselves accountable. The frameworks below cover information security, AI management, and the data protection laws our customers operate under.

ISO 27001:2022

ISO 27001:2022

Information Security Management System. Audited annually by an accredited third party.

In progress
SOC 2 Type I

SOC 2 Type I

Trust Services Criteria covering Security, Availability, and Confidentiality.

In progress
SOC 2 Type II

SOC 2 Type II

Operating effectiveness of controls across an audit window.

In progress
ISO 42001

ISO 42001

AI Management System. Scoped and underway as part of our security roadmap.

In progress
GDPR

GDPR

EU General Data Protection Regulation. Processes built around lawful basis, data subject rights, and minimisation.

Aligned
CCPA / CPRA

CCPA / CPRA

California consumer privacy rights, including access, deletion, and opt-out of sale.

Aligned
India DPDP Act

India DPDP Act

Digital Personal Data Protection Act, 2023. Built around consent, purpose limitation, and data principal rights.

Aligned
HIPAA

HIPAA

Administrative, physical, and technical safeguards available for regulated workloads under BAA.

In touch

Resources

The documentation behind our practices. Most reports are released under a mutual NDA. Our security team responds within two business days.

Controls

A summary view of the technical and organisational controls we operate every day, across security, privacy, and AI safety.

Access Security

  • SSO and MFA enforced for all production access
  • Role-based access control with least-privilege defaults
  • Unique user IDs and password hashing with salt
  • Idle session timeout and a documented joiner, mover, leaver workflow
  • Quarterly user access reviews

Network Security

  • Cloud firewall with intrusion detection and prevention
  • WAF, IP allowlisting, and port restrictions
  • mTLS at integration boundaries; OAuth 2.0 and JWT
  • Network segmentation between environments

Data Protection

  • AES-256 at rest, TLS 1.2 or higher in transit
  • CMEK and BYOK with configurable rotation
  • Configurable data residency for regulated deployments
  • Configurable retention with certified deletion at termination
  • PII masking, pseudonymisation, and redaction

Incident Response

  • Documented Incident Management Policy within the ISMS
  • Detection via centralised monitoring and dashboards
  • Customer notification within agreed SLAs of discovery
  • L1, L2, L3 triage with a mandatory lessons-learned retro

Change Management

  • Documented change policy with required PR review
  • Segregated development, staging, and production environments
  • Zero-downtime deploys; phased rollouts behind feature flags
  • Production data is never used in non-production environments

Vulnerability Management

  • Continuous code scanning in private repositories
  • Annual third-party penetration testing
  • Secure SDLC with security gates prior to production
  • High and critical findings closed before promotion

Availability & Recovery

  • 99.9% uptime SLA on enterprise contracts
  • Daily encrypted backups with real-time replication for critical data
  • Multi-AZ redundancy and failover
  • BCP and DR plan tested against agreed RPO and RTO targets

People & Organisation

  • Background verification for every hire
  • NDAs and confidentiality agreements at onboarding
  • Security and privacy training at hire, with annual refreshers
  • Dedicated InfoSec function with executive sponsorship

AI & Model Security

  • Inference-time guardrails against prompt injection
  • Input and output sanitisation with sensitive-content filtering
  • Versioned models, prompts, and evaluations with audit trail
  • Customer data is never used to train models for other customers

Talk to our security team

Have a question that isn't covered here? We're happy to help.

Common questions