Trust
Trust & compliance
Security teams are our buyers, so trust isn't a marketing layer — it's the product. Here's where we stand today, stated plainly.
Certifications & frameworks
- SOC 2 — our control register is continuously verified in CI; the Type II report is not yet issued
- ISO 27001 — planned to follow SOC 2
- EU data residency — primary data stores can be pinned in-region
- Tamper-evident (WORM) audit log of every enforcement action, streamable to your SIEM
Data handling
GraphDefend connects with scoped, read-only access and isolates every customer's data by tenant. We collect the metadata required to build your identity graph and assess risk — not the contents of your systems. A hybrid deployment is available, with the collector running on your own infrastructure.
Subprocessors & availability
A current list of subprocessors is available to customers and prospects under NDA. Contact us to request our security package.
Request our security package
Email support@graphdefend.com or reach out through the contact form for our SOC 2 control overview and architecture overview.