Security

Enterprise-grade security practices designed to protect your asset data

Compliance

Inspectr is certified to ISO/IEC 27001:2022 (certificate ISMS-4819-20260808, issued 8 August 2026, valid through 7 August 2029). We completed a SOC 2 Type I audit in July 2026; the Type II audit is underway. Our policies are reviewed and updated annually.

Report Available
AICPA SOC for Service Organizations

SOC 2 Type I

Certified
Johanson Group LLP, IAS-accredited ISO/IEC 27001 certification body

ISO/IEC 27001:2022

Audit In Progress

SOC 2 Type II

Security & Privacy Practices

Aligned with GDPR principles
CCPA/CPRA Compliant
Cyber Essentials Certified
Annual Policy Reviews

We maintain formal Information Security, Incident Response, and Business Continuity & Disaster Recovery policies. Our data handling practices are aligned with GDPR principles and designed to support customer compliance requirements.

View our Trust Center

Live controls, certifications, and audit documentation in our Trust Center.

Security Practices

Our comprehensive security program covers every aspect of how we build, operate, and protect the platform.

Infrastructure

All data is encrypted at rest and in transit (TLS 1.2+, AES-256). Production systems are hosted on AWS (SOC 2 Type II and ISO 27001 certified) with geo-redundant backups, continuous replication, and defined recovery objectives (RTO: 2-4 hours, RPO: <15 minutes for core platform services). Access is governed by least-privilege principles with mandatory MFA on all critical systems.

Secure Development

Our deployment pipeline includes automated SAST/DAST scanning, dependency vulnerability monitoring, and adherence to OWASP Top 10 secure coding standards. All production changes follow formal change management processes. Independent third-party penetration testing is performed periodically, with all findings remediated.

Data Privacy

Client data is never used to train shared models. Processing is limited to what's necessary under your agreement - no exceptions. We support data subject rights under GDPR and CCPA/CPRA, including access, rectification, erasure, and portability. International data transfers are governed by Standard Contractual Clauses where applicable. Data Processing Agreements are available on request.

AI & Learning

Your data is never used to train shared models, and nothing Inspectr learns about your organization is ever shared with or applied to anyone else.

Vendor Risk Management

All third-party providers undergo risk-based due diligence before engagement. Contracts include appropriate security, confidentiality, and data protection terms. Critical vendors are reviewed at least annually.

Incident Response

We maintain a documented Incident Response Plan with defined severity levels, prompt and prioritized response targets for critical incidents, and clear escalation paths. Breach notifications are issued in accordance with GDPR and applicable contractual requirements. The plan is tested annually through tabletop exercises.

Business Continuity

Our BCDR plan ensures service availability through automated backups, geo-separated storage, and tested restoration procedures. Backup integrity is validated quarterly for critical systems. The plan is reviewed and updated annually.

Security Questions?

Have questions about our security practices or need to request our policies? Our security team is here to help.