Enterprise-grade security practices designed to protect your asset data
Inspectr is certified to ISO/IEC 27001:2022 (certificate ISMS-4819-20260808, issued 8 August 2026, valid through 7 August 2029). We completed a SOC 2 Type I audit in July 2026; the Type II audit is underway. Our policies are reviewed and updated annually.


We maintain formal Information Security, Incident Response, and Business Continuity & Disaster Recovery policies. Our data handling practices are aligned with GDPR principles and designed to support customer compliance requirements.
Live controls, certifications, and audit documentation in our Trust Center.
Our comprehensive security program covers every aspect of how we build, operate, and protect the platform.
All data is encrypted at rest and in transit (TLS 1.2+, AES-256). Production systems are hosted on AWS (SOC 2 Type II and ISO 27001 certified) with geo-redundant backups, continuous replication, and defined recovery objectives (RTO: 2-4 hours, RPO: <15 minutes for core platform services). Access is governed by least-privilege principles with mandatory MFA on all critical systems.
Our deployment pipeline includes automated SAST/DAST scanning, dependency vulnerability monitoring, and adherence to OWASP Top 10 secure coding standards. All production changes follow formal change management processes. Independent third-party penetration testing is performed periodically, with all findings remediated.
Client data is never used to train shared models. Processing is limited to what's necessary under your agreement - no exceptions. We support data subject rights under GDPR and CCPA/CPRA, including access, rectification, erasure, and portability. International data transfers are governed by Standard Contractual Clauses where applicable. Data Processing Agreements are available on request.
Your data is never used to train shared models, and nothing Inspectr learns about your organization is ever shared with or applied to anyone else.
All third-party providers undergo risk-based due diligence before engagement. Contracts include appropriate security, confidentiality, and data protection terms. Critical vendors are reviewed at least annually.
We maintain a documented Incident Response Plan with defined severity levels, prompt and prioritized response targets for critical incidents, and clear escalation paths. Breach notifications are issued in accordance with GDPR and applicable contractual requirements. The plan is tested annually through tabletop exercises.
Our BCDR plan ensures service availability through automated backups, geo-separated storage, and tested restoration procedures. Backup integrity is validated quarterly for critical systems. The plan is reviewed and updated annually.