The section a procurement reviewer opens first, so it is written to be read first.
3.1 Security obligations
We maintain an information security programme with administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including encryption in transit and at rest, least-privilege access, logged and time-bounded production access, and annual third-party penetration testing.
We will not materially decrease the security of the service during a paid term. Where a control changes, the change is documented and available to the customer.
3.2 Audit rights
Customers receive the current security documentation package on request, and a summary of penetration test findings and remediation status annually.
SOC 2 Type II is in progress. Until the report exists we say so in this document rather than offering a certification we do not hold; on completion, the report will be provided under NDA and will satisfy the audit obligation in this clause. A customer with a regulatory requirement for an on-site or questionnaire-based audit may exercise it once annually on reasonable notice.
3.3 Incident notification
Confirmed security incidents affecting the customer's data are notified within 72 hours of confirmation, with a written report covering scope, cause, and remediation within ten business days.
Operational incidents follow the published severity ladder, beginning at P0 for a total loss of service.