Skip to content

Procurement-ready, on day one.

RegAlytics is infrastructure for GRC platforms, so the question “can we put your data inside our product?” comes up inside the first week. This page is the answer: certifications, data handling, uptime commitments, sub-processors, and responsible disclosure in one place. Bring it to your security reviewer. They will find what they need without raising a ticket.

Download the security pack

What your security team needs to see

SOC 2 Type II

Annual audit across the full control set. Report is available under NDA before contract signature, no back-and-forth required.

ISO 27001

Certified information security management system covering the platform, the data pipeline and the operations team that runs them.

99.9% uptime

Published SLA on the v3 REST, MCP and webhook endpoints. Historical performance is visible on the public status page.

Data handling and residency

Encryption in transit. TLS 1.2+ on every endpoint, HSTS enabled, no insecure fallbacks. Certificate management handled through an automated PKI with short-lived issuance.

Encryption at rest. AES-256 across primary stores, KMS-managed keys with audited rotation. Backups are encrypted with the same posture and stored in the same region as the primary.

Data residency. Primary hosting in the US with an EU region available for customers whose procurement requires it. No cross-region replication of customer data without written authorisation.

Logical separation per customer at the API layer.
Principle of least privilege for all internal access.
All operator access is audit-logged and reviewed monthly.

Uptime, incidents, and the humans who own them.

The platform runs a primary/secondary topology across regions, with automated failover on the read path and rate-limited graceful degradation on the write path. We publish a public status page, post-mortems on anything customer-visible, and a 15-minute response SLA on Sev-1 during business hours. After-hours on-call is rotated across engineering.

If you need to integrate our status feed into your own reliability tooling, we expose the status page via a JSON endpoint. Happy to share the URL and a sample payload during evaluation.

Testing, disclosure, and the sub-processor list

Pen testing. Third-party penetration test every 12 months against the public API, MCP server and admin plane. Summary letter shared under NDA. Interim testing fired on every major surface change.

Responsible disclosure. security@regalytics.ai is monitored by engineering, not a shared inbox. PGP key published on the site, 90-day resolution target for confirmed reports, and a public thank-you list for reporters who opt in.

Sub-processor list. Maintained at /legal/subprocessors with email notification before any addition. No hidden third parties, no surprise data flows, no "a partner of our partner" ambiguity.

Business continuity. Quarterly disaster-recovery drills with a documented RPO of 1 hour and RTO of 4 hours on the core data plane. Tabletop reviews with the executive team once a year.

RegAlytics Branding

Ask us for the trust pack

The full trust pack (SOC 2 Type II report, ISO 27001 certificate, pen-test summary, DPA template, sub-processor list, BCDR summary) is available under a standard NDA during evaluation. Most teams get through the diligence review in a single 30-minute call. That is the pitch: your procurement team should not be the thing that slows down the integration.

Start the security review.

Tell us who on your side will run the diligence and we will send the trust pack, the NDA template if you need one, and a calendar link for a 30-minute review call. Most reviewers finish reading before the call even starts.

Name(Required)