Security & Compliance
Security is foundational to a platform people trust with decisions about their own money. This page summarizes the controls, certifications, and practices that keep your data and workflows protected.
Our approach
We build security into every layer of SIP — from how code ships, to how infrastructure is provisioned, to how staff access production. Our program is designed around least privilege, defense in depth, and continuous monitoring.
Security is owned by a dedicated team and reviewed by leadership on a recurring basis. Policies are documented, enforced, and reviewed at least annually.
Certifications & attestations
SIP maintains independent, third-party validation of its controls:
| Framework | Status | Scope |
|---|---|---|
| SOC 2 Type II | Maintained | Security, Availability, Confidentiality |
| ISO/IEC 27001 | Certified | Information Security Management System |
| GDPR | Compliant | EU/UK personal data processing |
| CCPA / CPRA | Compliant | California resident data |
Reports and certificates are available to customers and prospects under NDA.
Infrastructure & hosting
SIP runs on leading cloud infrastructure in SOC 2 / ISO 27001 certified data centers. Production is logically isolated, deployed across multiple availability zones, and hardened using infrastructure-as-code with peer-reviewed changes.
Encryption
- In transit — all traffic is encrypted with TLS 1.2+; older protocols are disabled.
- At rest — data is encrypted using AES-256.
- Key management — keys are managed by a dedicated key-management service with strict access controls and rotation.
Access controls
Access to production systems follows least-privilege principles. We enforce SSO and mandatory multi-factor authentication for staff, role-based access, and just-in-time elevation with logging. Access is reviewed regularly and revoked promptly on role change or departure.
For customers, we offer SSO/SAML, role-based permissions, and audit logs on eligible plans.
Application security
Security is embedded in our SDLC. We use mandatory code review, automated dependency and static analysis scanning, and a hardened CI/CD pipeline. Independent penetration tests are conducted at least annually, and findings are tracked to remediation.
Monitoring & incident response
We continuously monitor infrastructure and applications for anomalies and security events, with centralized logging and alerting. Our documented incident-response plan defines severity levels, escalation, and communication. We notify affected customers of confirmed incidents without undue delay and in line with contractual and legal obligations.
Business continuity & disaster recovery
Data is backed up on a regular schedule with encryption, and backups are tested for restorability. Our business-continuity and disaster-recovery plans define recovery objectives and are exercised periodically to ensure resilience against disruption.
Vendor & subprocessor management
We assess the security posture of vendors before onboarding and on an ongoing basis. Subprocessors that handle personal data are bound by data-protection terms consistent with our Data Processing Addendum. A current list of subprocessors is available on request.
Privacy & compliance frameworks
Our practices are designed to support customer compliance with GDPR, UK GDPR, and CCPA/CPRA. We offer a Data Processing Addendum incorporating the EU Standard Contractual Clauses for international transfers. See our DPA and Privacy Policy for details.
Responsible disclosure
We welcome reports from security researchers. If you believe you've found a vulnerability, please email security@sipintel.com with details and steps to reproduce. We commit to acknowledging reports promptly, investigating in good faith, and not pursuing legal action for good-faith research conducted under our disclosure guidelines.
Contact the security team
For security questions, audit requests, or to report an issue, contact security@sipintel.com. Enterprise customers can request our full security package, including our SOC 2 report and latest penetration-test summary, under NDA.