All security, privacy, and compliance documents consolidated for procurement, legal, and security teams. Bookmark this page for your vendor risk questionnaires.
All SOC 2 controls are implemented and production-ready. Formal external audit engagement is underway for H2 2026 certification. G8KEPR discloses this status transparently — contact us for our current controls evidence package.
All documents available immediately — no NDA required for standard references. Enterprise agreements and audit reports available under NDA.
Privacy Policy
How we collect, use, and protect your data
Terms of Service
Terms governing use of G8KEPR services
Data Processing Agreement (DPA)
GDPR-compliant DPA; sign online or request enterprise MSA version
Master Service Agreement (MSA)
Available for enterprise customers — contact sales
Subprocessors List
All third-party sub-processors we use and their regions
Security Overview
Controls, encryption standards, incident response overview
SOC 2 Type II Readiness
Current control status — external audit engagement H2 2026
Vulnerability Disclosure Policy (VDP)
How to report security issues responsibly
Incident Response Policy
How we detect, respond to, and communicate incidents
At-a-glance summary for security questionnaires
TLS 1.3 in transit · AES-256 at rest · Ed25519 signing keys in HSM
Append-only row trigger · Auth and domain events hash-chained, verified daily · 1-year retention
RBAC with org-level isolation · MFA enforced · JWT RS256 rotation 90d
Internal red-team self-assessment 2026-04 · 5 high and 2 medium findings, all fixed · No third-party test yet
US-East (NYC3) hosted · No EU region yet · Self-host option
< 1 hour detection target · Customer notification within 24h · Status page at /status
Need custom questionnaire responses, additional audit artifacts, or a security call? Our security team responds within one business day.