Skip to content
Trust

Trust & compliance

Security teams are our buyers, so trust isn't a marketing layer — it's the product. Here's where we stand today, stated plainly.

Certifications & frameworks

  • SOC 2 — our control register is continuously verified in CI; the Type II report is not yet issued
  • ISO 27001 — planned to follow SOC 2
  • EU data residency — primary data stores can be pinned in-region
  • Tamper-evident (WORM) audit log of every enforcement action, streamable to your SIEM

Data handling

GraphDefend connects with scoped, read-only access and isolates every customer's data by tenant. We collect the metadata required to build your identity graph and assess risk — not the contents of your systems. A hybrid deployment is available, with the collector running on your own infrastructure.

Subprocessors & availability

A current list of subprocessors is available to customers and prospects under NDA. Contact us to request our security package.

Request our security package

Email support@graphdefend.com or reach out through the contact form for our SOC 2 control overview and architecture overview.