Enterprise-grade security with privacy-by-design architecture. Our comprehensive security posture protects your data with SOC 2 compliance, advanced encryption, and robust access controls.
security@partneraz.com (PGP available on request)
TLS 1.2+ in transit; AES‑256 at rest
SSO/OIDC (Google/Microsoft), enforced MFA, least‑privilege RBAC
Only fields required for matching; PII is optional and scoped
Point‑in‑time backups; RPO ≤ 24h, RTO ≤ 12h
Centralized logs, anomaly alerts, WAF/Rate‑limit on all endpoints
SOC 2 Type I (Q2), Type II (Q4); ISO 27001 pilot; HIPAA‑lite controls
Primary region: Canada; failover: U.S. (no failover without client consent for regulated data)
Tenant‑scoped row‑level security; vendor/buyer workspaces logically isolated
Default 18‑month retention for app submissions; hard delete within 30 days of request
Cloud hosting, email delivery, observability—listed on /security/subprocessors with change notice ≥ 30 days
DPAs available on request; SCCs for cross‑border transfers
Threat modeling on new features; automated SAST/DAST on each PR; dependency scanning with pinned versions
Managed KMS; no secrets in source; short‑lived tokens only
Server‑side validation, allow‑lists, output encoding; file uploads virus‑scanned; PDF/image content‑type locked
Per‑IP and per‑account throttles; bot detection on public forms
CVE triage SLA—Critical 24h, High 72h, Medium 14d, Low 30d
Annual third‑party test (summary posted); re‑test after major releases
No; our healthcare discovery avoids ePHI. If a tenant needs PHI, we'll require a HIPAA BAA and segregated stack.
Yes, we provide Data Processing Agreements and Standard Contractual Clauses upon request.
Enterprise plan can pin to CA or EU with no cross‑region replication.
Have specific security, compliance, or data protection questions? Our security team is here to help.