Skip to main content
Security overview

Security infrastructure for support operations

Encrypted by default, multi-tenant isolated, audit-trailed per action. The DPA, sub-processors, and audit summaries you'd expect from a support stack.

Encryption

TLS 1.3 · AES-256

In transit and at rest

Audit logs

Per action

Tools, configs, approvals — recorded

Tenant isolation

Enforced

Data never crosses tenant boundaries

Sub-processors

Disclosed

Listed with change notifications

Security Framework

Defense in depth

Layered controls — encryption, operational gates, and data handling — applied at every step of the support workflow.

Encryption
Industry-standard encryption in transit and at rest
  • TLS 1.3 in transit
  • AES-256 at rest
  • Tenant-isolated key management
  • Encrypted backups with separate keys
Operational controls
Per-action audit trails and approval gates
  • Audit logs per action — tool, config, approval
  • Immutable workflow snapshots on publish
  • Approval gates by intent, amount, and risk
  • Regular third-party penetration testing
Data handling
GDPR-aligned data handling with DPA on request
  • Data minimization at collection
  • Right to access and deletion
  • Sub-processors disclosed and notified
  • Region-aware data residency on Enterprise
Audits and standards

Aligned to the frameworks your procurement asks for

Audit reports, DPAs, and sub-processor lists are available on request — no waiting for a sales call.

Audits and frameworks
SOC 2 Type II

Audit in progress; summary available on request under DPA.

ISO 27001

Controls aligned to ISO 27001; audit roadmap shared on request.

GDPR-aligned

Data handling aligned to GDPR; DPA available on request.

CCPA-aligned

California consumer privacy rights honored on request.

Engineering practice
OWASP Top 10

Application security follows OWASP guidance; reviewed on every release.

NIST CSF

Operational controls map to the NIST Cybersecurity Framework.

Penetration testing

Independent third-party tests with remediation tracked to closure.

Sub-processors

Disclosed list with change notifications — see /sub-processors.

Trust resources

The documents your security team needs

Sub-processors are public; DPAs, BAAs, audit summaries, and penetration test reports are available on request.

Sub-processors

Public list with change notifications

View

DPA, BAA, audit reports

Available on request via hi@subport.io

Request

Privacy policy

What we collect, why, and how long we keep it

Read

Responsible disclosure

Report a vulnerability to security@subport.io

Email

Bring security into the loop early.

Most teams hand us off to security review at procurement. Looping them in before then makes the deal move faster.

14-day free trial
No credit card required
Cancel anytime