Skip to main content

Trust

Security questionnaire facts

Answers for procurement and security reviews, sourced from public Capgo pages and documentation. For SOC 2, ISO 27001, detailed control mappings, and completed questionnaires, use the trust portal (request access under NDA). Certification reports are not distributed by email.

Last reviewed: October 6, 2026.

How to use this page

Each section summarizes public Capgo sources and, where noted, approved vendor questionnaire answers (control IDs shown as tags). Follow linked primary sources for contract wording. For SOC 2 Type 2, ISO 27001:2022, and report PDFs, use trust.capgo.app (NDA signed there, not by email). Items under Topics not stated publicly still need the trust portal or security@capgo.app.

Related pages: Trust , Security policy , Subprocessors , DPA , Enterprise .

Company and product

  • Legal entity: Digital Shift OÜ (register code 14236508), Sepapaja 6, 15551 Tallinn, Estonia. Imprint .
  • Product: Live updates (OTA) for Capacitor, Ionic, Cordova, and Electron apps, plus native iOS and Android builds on Capgo Cloud. Live updates , Native build .
  • Open source: Updater plugin and Capgo plugins under MPL-2.0; backend under AGPL-3.0 with self-hosting available. GitHub .
  • Deployment options: Hosted Capgo Cloud, plus Enterprise hosted, dedicated, hybrid, and licensed self-hosted options. Enterprise .
  • Governing law: Estonia per the Terms of Service .

Vendor questionnaire answers

Who is accountable for security functions? OS.3
The CEO is the designated Information Security Officer, accountable for security policy, governance, strategy, threat and vulnerability management, and incident response, supported by the engineering team.
Do you contractually require all vendors to perform background checks? HR.2
No. Our infrastructure vendors screen their own personnel under audited SOC 2 and ISO 27001 programs, which we review annually. All Capgo staff are background checked before access is granted.
Do you run simulated phishing exercises at least annually? HR.4
No. Phishing awareness is covered in onboarding and annual security training, and MFA is enforced on all accounts.
Is return of assets and access removal documented at termination? HR.6
Yes. Our termination checklist covers return of company assets and removal of all access within 1 business day.

Hosting and subprocessors

The authoritative list of DPA sub-processors, processing locations, and transfer mechanisms is on the subprocessors page (not the trust portal subprocessors counter). Current DPA sub-processors include:

  • Supabase, Inc. (London, UK): primary database, authentication, account data, application and bundle metadata, device identifiers.
  • Cloudflare, Inc. (global, including USA): edge CDN, Workers, Durable Objects, R2, security services, live-update delivery.
  • Google Cloud (Hong Kong, Tokyo, Sydney, Johannesburg, Milan, Jeddah, Mumbai, Sao Paulo, Columbus): database read replicas and regional infrastructure.
  • Scaleway SAS (Paris, France): native build infrastructure, artifacts, and workflow data.

Customer CI is not a Capgo DPA sub-processor: Capgo does not link customer GitHub repositories or pull source from them. Typical automation uses customer CI (for example GitHub Actions) with a Capgo API token to upload bundles or submit native build requests. GitHub Actions integration , CI/CD integration .

Capgo also uses controller-side services for its own business (examples listed on the subprocessors page include Stripe, Bento, PostHog, CodeRabbit, and SonarCloud). Apple and Google are independent controllers for store publishing when customers use their own developer accounts.

The Trust page states that Cloudflare, Supabase, and isolated CI pipelines enforce MFA, secret management, and safeguarded environments, and that critical vendors maintain SOC 2 attestation reviewed annually.

For hosting questions, prefer the subprocessors list over older imprint hosting lines that may not reflect current vendors.

Vendor questionnaire answers

What URL do customers use to access the hosted application? HAS.7
https://console.capgo.app
Where is the service hosted? HAS.8
At cloud service providers: serverless on Cloudflare Workers with managed Supabase PostgreSQL in London, Google Cloud read replicas, and Scaleway in Paris for native builds. See the subprocessors page for the current list.
Is the service hosted in colocation facilities you operate? HAS.9
No. Capgo does not operate colocation or owned data centers.
How is customer data separated in the multi-tenant service? HAS.10
Logical multi-tenant separation. Database records are isolated per organization by PostgreSQL Row Level Security and role-based authorization. Bundles are stored in object storage under per-organization and per-app paths. Customers can enable end-to-end bundle encryption with their own keys.
Does each customer receive separate database credentials or schemas? HAS.11
No separate database per customer. Tenant isolation is enforced by Row Level Security and application authorization rather than per-tenant database credentials.
How do administrators manage production? HAS.21
Through cloud provider web consoles and their CLIs and APIs over TLS, using MFA-protected accounts and scoped API tokens. Production database and SSH access are not exposed to the public internet.
Which common production controls are not in place? HAS.28
We do not operate a dedicated SIEM or corporate VPN. Cloudflare provides DDoS protection and a web application firewall at the edge, production hosts are deny-by-default, and administrative access uses MFA-protected provider consoles.
Do databases run under non-privileged service accounts? HAS.31
Yes. The database is managed PostgreSQL operated by Supabase. Application connections use dedicated non-superuser roles, and user-facing access is subject to Row Level Security.
Does the application tier run under a non-privileged service account? HAS.32
Yes. The web tier runs on Cloudflare Workers in sandboxed V8 isolates, with no operating system or root account exposed to our code.
Do you maintain a physical security policy? PE.1
Yes, reviewed and approved annually. Capgo has no offices or data centers. The policy covers remote work, endpoints, and oversight of our cloud providers facilities.
What physical controls protect your environment? PE.2
Capgo has no offices or data centers. All production runs in Cloudflare, Supabase, Google Cloud, and Scaleway facilities whose physical controls are covered by independent audits that we review annually.
Are visitors permitted at your facilities? PE.4
Not applicable at Capgo. We operate fully remote with no owned premises. Data center visitor controls are handled by our cloud providers.

Data residency and regions

For standard Capgo Cloud, Supabase processes the primary database, authentication, account data, app and bundle metadata, and device identifiers in London, United Kingdom. Google Cloud provides database read replicas and regional infrastructure in Hong Kong, Tokyo, Sydney, Johannesburg, Milan, Jeddah, Mumbai, Sao Paulo, and Columbus. Bundle storage and live-update delivery use Cloudflare’s global infrastructure, including the USA. Enterprise can use regional endpoint routing for the live-update path or a licensed self-hosted deployment when different control is required. The up-to-date sub-processor list contains the full provider, location, and transfer details.

EU plugin data path (opt-in): Set updateUrl, statsUrl, and channelUrl to the full EU endpoints: https://plugin.eu.capgo.app/updates, https://plugin.eu.capgo.app/stats, and https://plugin.eu.capgo.app/channel_self. All three must be set together so related live-update data is stored in Europe. Data location documentation .

Account and console data: Public documentation describes the EU option for the plugin data path. A separate EU-only option for account or console data is not documented publicly (see gaps ).

Strict residency: Licensed self-hosting provides control over infrastructure, logs, retention, and network boundaries. HIPAA-sensitive deployment options .

Encryption

  • In transit: HTTPS/TLS for data transmission. Compliance documentation , DPA .
  • At rest: Encryption at rest for platform data where applicable, per compliance documentation and DPA security measures.
  • Optional bundle encryption (customer keys): End-to-end bundle encryption with customer-managed keys (RSA-4096 and AES-256-GCM in Encryption V2). Encryption documentation . Protects against disclosure by Capgo, storage providers, and CDNs; does not make shipped web assets impossible to reverse engineer.
  • Integrity: Bundles are checksum-verified; optional per-app encryption with your own key. Compliance documentation .
  • API keys: Secure API keys are hashed; the raw key value is not stored on Capgo servers. Organization security documentation .

Vendor questionnaire answers

Is customer data encrypted at rest in databases and object storage? HAS.13
Yes. Databases, backups, and object storage are encrypted at rest with AES-256 by our cloud providers, with keys stored and rotated in the providers key management systems. Customers can additionally encrypt bundles end to end with their own key pair.
Does each customer have a distinct encryption key for platform storage? HAS.14
No for platform storage. Provider-managed keys are shared across tenants. For bundles, customers can enable end-to-end encryption with their own RSA key pair whose private key Capgo never holds.
Can personnel who access encrypted production data obtain encryption keys? HAS.15
No for platform keys. Encryption keys for data at rest are held in our cloud providers key management systems and are not accessible to Capgo personnel. Private keys for end-to-end bundle encryption are held only by the customer.
Can customers supply customer-managed keys for platform storage encryption? HAS.16
No for platform storage. Customers can encrypt bundles end to end with their own key pair so Capgo does not hold the key for that content.

Authentication and access control

Customer controls

  • SSO (SAML 2.0): Enterprise plans; domain verification via DNS TXT; optional enforce SSO; new SSO users provisioned with the read role. Enterprise SSO documentation .
  • MFA: Organization super admins can require 2FA for all members; members without 2FA are blocked from the web dashboard and CLI. Organization security documentation .
  • Password policy: Configurable minimum length (6 to 128), uppercase, number, and special character requirements.
  • API keys: Enforce secure (hashed) keys and optional expiration (1 to 365 days).
  • RBAC: Organization roles (super admin, admin, billing admin, member) and app roles (admin, developer, uploader, reader) with per-channel overrides. Features documentation .

Capgo personnel

Access is limited to authorized personnel who need it for support, abuse prevention, and operational reliability; personnel are trained in GDPR and data privacy per the DPA .

Password and email update flows may depend on Supabase Auth session and re-verification settings. Security policy .

Vendor questionnaire answers

Is a VPN required for remote access to your network? AC.11
No. There is no corporate network to connect to. Staff manage production through cloud provider consoles and APIs over TLS with enforced MFA. Production database and SSH access are not exposed to the public internet.
Is automatic screen lock with password re-authentication enforced within 15 minutes or less? AC.12
Yes. Automatic screen lock with password re-authentication is enforced and monitored on all endpoints through our device compliance agent.
Is access provisioned with role-based, least-privilege controls and approval before credentials are issued? AC.13
Yes. Access is provisioned through role-based access control on a least-privilege basis and requires approval before credentials are issued.
Is access reviewed when a user changes role? AC.14
Yes. Our compliance monitoring platform alerts the security owner to update access whenever a role changes, and all access is also reviewed periodically.
Is there an industry-standard password policy owned by security leadership and approved annually? AC.15
Yes. Our documented password and login policy is owned by the Information Security Officer and reviewed and approved annually by senior management.
Must users reset or set their own password at first sign-on? AC.16
Yes. We do not issue reusable initial passwords. New users receive a single-use invitation or temporary credential and must set their own password at first sign-in, with MFA required.
Are initial passwords or invitation links randomly generated and unique per user? AC.17
Yes. Invitation links and any temporary credentials are randomly generated and unique to each user.
Are vendor default accounts and settings changed before production use? AC.18
Yes. Production runs on managed serverless services without vendor default accounts, and default settings are reviewed and hardened under our configuration management controls before use.
Do you use a centralized directory service for workforce identity? AC.22
Yes. Google Workspace is our central identity directory, with 2-Step Verification enforced for all accounts, and is used for sign-in to core systems where supported.
Do passwords expire on a fixed schedule? AC.23
No fixed rotation. Following NIST SP 800-63B, passwords are not rotated on a fixed schedule. They are changed on any sign of compromise, and MFA is enforced on all systems.
Do workforce passwords require at least 8 characters with upper, lower, number, and special character? AC.24
Yes for workforce accounts through our identity provider settings, with MFA required on all systems.
Is password history enforced? AC.25
No fixed history rule for workforce passwords. Reuse risk is addressed by MFA on all systems and unique passwords generated by a password manager.
Are commonly used passwords blocked automatically? AC.25.1
Yes. Our identity provider rejects weak and commonly used passwords.
Can only registered, compliant devices access internal systems? AC.29
There is no corporate network. Internal systems are accessed only from inventoried, registered endpoints that pass device compliance checks for encryption, malware protection, patching, and screen lock.
Are dormant accounts disabled automatically after inactivity? AC.30
No inactivity timer. Access is removed within 1 business day of offboarding, and periodic access reviews by the Information Security Officer identify and remove unused accounts.
Is MFA enforced for all staff with remote production administrative access? HAS.20
Yes. MFA is enforced for all staff accounts with access to production and other critical systems.
Is MFA available and enforceable for all Capgo Cloud application users? HAS.20.1
Yes. TOTP MFA is available to every user, and organization administrators can enforce it for all members, which blocks dashboard and CLI access for anyone without MFA.
What sign-in methods does the Capgo Cloud console support? HAS.27
Users sign in with email and password plus TOTP MFA, which customers can enforce for all members. SAML 2.0 SSO with optional enforcement is available on the Enterprise plan. CLI and CI access uses scoped API keys with optional mandatory expiry.
Are accounts locked out after a fixed number of failed login attempts? HAS.35
No fixed per-account lockout. Sign-in attempts are rate limited by our authentication provider, and customers can enforce MFA or SAML SSO for all of their users.
Do privileged staff have direct production database access? HAS.30
Yes, but limited. Direct production database access is limited to 2 authorized engineers, protected by MFA, not exposed to the public internet, and reviewed periodically.
Does your asset inventory identify internet-facing systems? AM.2.1
Yes. Our infrastructure inventory and architecture diagram identify all internet-facing endpoints.
Is secure disposal of data and media governed by formal protocols? AM.3
Yes. Disposal follows our Data Classification, Retention, and Deletion Policy. Destruction of storage media in data centers is performed by our cloud providers under their audited controls.
Are security configuration baselines defined and reviewed at least every 12 months? AM.5
Yes. Configuration baselines for our cloud services and endpoints are defined under our configuration management controls and reviewed at least annually with our policies.
Are operating systems hardened to necessary ports, protocols, and services? AM.6
Yes for production: serverless on managed platforms with ingress limited to HTTPS on designated endpoints and deny-by-default firewall rules. Scaleway macOS build runners are the main OS Capgo operates for native builds.
What endpoint protections are deployed on staff devices? CO.4
All endpoints run malware protection and full-disk encryption, monitored by our device compliance agent. Host IPS and USB port blocking are not deployed. Customer data is processed in our cloud production systems.
Is full-disk encryption deployed on staff endpoints? CO.5
Yes. Full-disk encryption is enforced and monitored on all endpoints. Databases and cloud backups are encrypted at rest in our cloud providers. We do not write backups to removable media.
Do you operate a DLP tool that monitors outbound traffic and USB? CO.5.1
No. Customer data stays in access-controlled cloud systems, endpoints are fully encrypted and monitored, and data handling rules are defined in our Acceptable Use and Data Classification policies.
Are firewall rules reviewed or recertified regularly? CO.8
Yes. Production ingress rules are deny-by-default and limited to HTTPS endpoints, and are reviewed at least annually as part of our configuration and access reviews.
Do you maintain network diagrams showing inbound and outbound connections? CO.9
Yes. Our architecture and network diagrams show system boundaries and the connections between Capgo, our cloud providers, and customers, and are maintained with the system inventory.
May staff read corporate email on personal computers? CO.14
Staff may use registered personal laptops enrolled in our device compliance agent, which enforces disk encryption, malware protection, screen lock, and patching. Email access requires MFA.
Is MFA required for remote access to corporate email? CO.15
Yes. 2-Step Verification is enforced at the domain level for all Google Workspace accounts.
How often must users re-authenticate with MFA? CO.16
MFA is required at every new sign-in and on any new device. Session length follows our Google Workspace session control setting (currently 14 days for trusted sessions).

Logging, monitoring, and incidents

  • Customer audit logs: Audit trail for logins, permission changes, bundles, channels, and organization changes. Features documentation . Enterprise includes audit logs, 90-day org statistics, and 90-day device logs per the Enterprise page.
  • Monitoring: Dedicated runbooks, 24/7 monitoring, and founder-led incident response playbooks per the Trust page .
  • Status: Public uptime and incidents at status.capgo.app (referenced in the support policy ).
  • Personal data breach notice (processor): Notify customers without undue delay, not later than 48 hours after becoming aware, by email with periodic updates, per the DPA .
  • Updater fail-safe: If the update service does not respond within 3 seconds, the plugin cancels the request and opens the app normally per the support policy .

Vendor questionnaire answers

Are audit logs retained for at least three years? AC.26
No. Audit events are generated for security-relevant actions on critical systems and reviewed with alerting to detect anomalous activity. Logs are retained according to our Logging Policy and each platform retention settings, which is less than three years.
Do production logs feed a SIEM? AC.27.1
No dedicated SIEM. Production logs are collected in our cloud providers logging and observability tools with alerting and are reviewed for anomalous activity.
What network defenses and monitoring are in place? CO.3
Cloudflare provides edge firewall, web application firewall, and DDoS protection. Production hosts use deny-by-default rules, and Google Workspace filters email and spam. We do not operate a dedicated SIEM; logs are monitored with alerting in our providers tools.
Does your incident response plan cover common incident types? IE.2
Yes. Our incident response plan covers malware, denial of service, unauthorized access, unauthorized physical access, data loss, lost laptops, and ransomware. Physical intrusion scenarios apply to endpoints only because we operate fully remote with no owned premises.
Do you maintain a contracted incident response firm on retainer? IE.3
No retainer today. Our incident response plan provides for engaging an external incident response firm when needed.
Is the incident response plan tested and updated at least annually? IE.3.2
Yes. The incident response plan is reviewed and approved annually by senior management, and we run an annual tabletop exercise.
Is there a protocol for engaging law enforcement? IE.6
Yes. Our incident response policy defines notification of customers and other stakeholders, and we maintain contacts with relevant authorities, including law enforcement, as part of our ISO 27001 program.

Backup, availability, and SLA

  • Backups, redundancies, encryption, and access controls per DPA security measures.
  • Regional replication and read replicas per Enterprise and subprocessors documentation.
  • Enterprise uptime SLA: 99.9% monthly with service credits from 10% to 30%. SLA .

Backups are tested periodically for integrity and restorability, with recovery procedures exercised annually (see vendor questionnaire answers below). Specific RPO and RTO targets are not published on capgo.app.

Vendor questionnaire answers

Are backup recoveries tested at least annually? CO.6
Yes. Backups are tested periodically for integrity and restorability, and recovery procedures are exercised annually.

Vulnerability management and disclosure

  • Code scanning: SonarCloud and Snyk; critical issues blocked from production per the Trust page and compliance documentation .
  • Pull request review: CodeRabbit AI review on pull requests per compliance documentation.
  • Penetration testing: Independent penetration testing per the Trust page. Vendor, date, and report availability are not public; use the trust portal for evidence requests.
  • Patching targets: Critical within 7 days and high within 30 days per our Vulnerability Management Policy (see vendor questionnaire answers below).
  • Disclosure: Report via GitHub Security Advisories (also capacitor-updater and CLI per security.txt ). Response within 7 business days per the security policy . Paid reports via bug bounty .

Vendor questionnaire answers

What security testing is required before production release? HAS.4
Every pull request runs automated tests, linting, static analysis (SonarCloud and a mandatory security scan), and automated code review before merge, and production changes are approved by management. DAST is not part of the release pipeline. An annual third-party penetration test covers the running application.
What is the patching cadence for critical and high vulnerabilities? VM.7
Critical: within 7 days. High: within 30 days, per our Vulnerability Management Policy.

Certifications and how to request evidence

Public statements include:

  • SOC 2 Type 2 completed (Type II) per compliance documentation .
  • ISO 27001:2022 certified per compliance documentation and trust portal.
  • Trust portal badges for SOC 2 Type 1, SOC 2 Type 2, SOC 3, ISO 27001, and GDPR at trust.capgo.app .

How to get reports: Visit trust.capgo.app , use Request Access for SOC reports, ISO evidence, security questionnaires, and control details under NDA. Do not expect certification PDFs by email.

Enterprise security review packets can include a SOC 2 report, DPA template, and architecture notes per the Enterprise page , still via the trust portal process for formal evidence.

Full SOC 2 and ISO audit reports, auditor opinions, and detailed scope are available only through the trust portal. Public marketing pages do not reproduce report PDFs.

Vendor questionnaire answers

Is there a non-retaliation process for internal compliance reporting? CP.3
Yes. Staff can report concerns through documented reporting channels defined in our policies, and our Code of Business Conduct protects good-faith reporters from retaliation.
Do vendor contracts include security provisions? OS.7
Yes. Our infrastructure providers agreements and DPAs cover access controls, breach notification, sub-processor security, and data ownership. Audit rights are exercised through their independent SOC 2 and ISO 27001 reports.
Do you perform vendor security due diligence? OS.8
Yes. Vendors are identified and risk rated in an annual vendor risk assessment that reviews their security attestations, including access controls, MFA, and encryption, with security commitments and incident notification in their contracts.
Is there a defined process for security policy exceptions? SP.4
Yes. Exceptions are documented, risk assessed, approved, and tracked under our Policy Management and Exception Handling policy.
Do you maintain cyber insurance? RM.5
No cyber insurance policy today.

Privacy and DPA

  • DPA: Accepted automatically when using the product; customer is controller, Capgo is processor; SCCs with sub-processors; breach notice and assistance obligations. DPA (last updated June 10, 2026 on the English page).
  • Signed DPA / NDA: Available on Enterprise per the Enterprise page.
  • Data collected by the updater (default): App ID, versions, platform, app-scoped device ID, bundle, channel, OS, plugin version, request country, and IP. Capgo does not collect names, emails, or advertising IDs by default. Optional custom_id and stats metadata may contain personal identifiers if your app sends them. HIPAA-minimum deployments should omit those fields and disable allow_device_custom_id. The device ID is pseudonymous personal data where GDPR applies. Compliance documentation .
  • Disable explicit statistics: Set statsUrl to an empty string to stop explicit statistics reports. When updateUrl remains enabled, Capgo can still store billing MAU, device inventory, and update-decision records required for live updates and billing. HIPAA compliance documentation .
  • Retention: Configurable bundle retention; operational records retained for service operation, security, billing, and support without a fixed public period.
  • No sale of service data: Stated in the DPA and Data Policy .

Also see Privacy Policy and Subprocessors (30-day change notice).

HIPAA-sensitive deployments

Capgo Cloud is not currently presented as a HIPAA-compliant hosted statistics processor per HIPAA compliance documentation . Enterprise plans can include a Business Associate Agreement (BAA) for healthcare customers per the HIPAA compliance page .

Deployment options for stricter reviews include EU endpoints, disabling explicit statistics (with the limits above), self-hosted statistics, and licensed self-hosting (see the HIPAA compliance page).

Generative AI

By default, Capgo does not send customer data to any AI provider. Internal development may use AI coding assistants on Capgo own source code only. If a customer opts in to build-log diagnostics, those logs are processed per request by Cloudflare Workers AI (see the subprocessors page ), with no retention by the AI service and no training use.

Vendor questionnaire answers

Do you use off-the-shelf generative AI tools that could process customer data? GAI.2
By default, customer data is not processed by off-the-shelf generative AI tools. Capgo uses AI coding assistants only for development on Capgo own source code, not on customer data. The only customer-facing exception is optional build-log diagnostics: when a customer opts in, those logs are processed per request by Cloudflare Workers AI, a listed sub-processor, with no retention by the AI service and no use for model training.
Is customer data sent outside your environment for AI analysis? GAI.3
By default, customer data is not sent to any external AI provider for analysis. The only exception is optional build-log diagnostics: when a customer opts in, those build logs are processed per request by Cloudflare Workers AI (listed on our subprocessors page), with no retention by the AI service and no use for model training.
Do you test AI outputs for unfair or discriminatory outcomes? GAI.10
Not applicable. AI is used only for technical build-log diagnostics and internal development assistance, and makes no decisions about individuals.
Does AI processing avoid reliance on protected characteristics? GAI.11
Yes. The customer-facing AI feature processes technical build logs only and does not use personal or protected characteristics.
Is AI output governed with human review and monitoring? GAI.12
Yes. Customer-facing AI output is advisory only and shown to the developer, who decides what to do. It takes no automated action. The feature is opt-in and covered by our risk assessment and vendor management processes.
Is access to AI components least privilege? GAI.13
Yes. The AI feature runs inside our production platform under the same role-based, least-privilege access controls, and the model service does not store customer data.
Do you maintain an inventory of AI models, data sources, and components? GAI.15
Yes. Our vendor and system inventories list the AI service, the models used, and the data sources that feed it.
How long is customer input retained in the AI system? GAI.16
By default, no customer content is sent to the AI service. When a customer opts in to build-log diagnostics, logs are processed per request by Cloudflare Workers AI and are not retained by that service or used for model training. Build logs stored in Capgo systems follow our standard data retention policy.

Contacts

Topics not stated publicly

The following are commonly asked in questionnaires but are not answered on public Capgo pages. Request details through the trust portal or security@capgo.app.

  • SOC 2 report period, scope, and auditor letter detail beyond what the trust portal provides
  • Penetration test vendor, date, and summary letter (annual testing is confirmed under Vulnerability management)
  • Published RPO and RTO numeric targets
  • Exact log retention periods per system beyond the less-than-three-years summary under Logging, monitoring, and incidents
  • TLS minimum version, cipher suites, and platform key management rotation details
  • SCIM provisioning
  • Data Protection Officer or EU representative contact
  • Specific customer data deletion timeline after contract termination
  • PCI DSS, FedRAMP, CSA STAR, or TISAX certifications (not claimed publicly)