Our Security Posture, Live.
We publish our compliance evidence, certifications, and security controls in real time — so you never have to ask for a questionnaire again.
99.99%
Uptime
2,847
Evidence Items
8
Sub-Processors
Continuously Audit-Ready
Compliance scores are pulled live from Chequr's evidence engine — not a quarterly snapshot.
SOC 2 Type II
Prescient Assurance
ISO 27001
Bureau Veritas
HIPAA
Internal Audit
GDPR
DPO Assessment
Third-Party Attestations
Independently audited, continuously monitored. Download reports or request access under NDA.
SOC 2 Type II
Annual third-party audit covering Security, Availability, and Confidentiality trust service criteria.
ISO 27001
Information Security Management System (ISMS) certified to the international standard.
HIPAA
Health Insurance Portability and Accountability Act compliance with full BAA execution support.
GDPR
General Data Protection Regulation compliance for all EU/EEA data subjects and processing activities.
15/16 Controls Passing
Every control is tested continuously by Chequr's agents. Evidence is collected automatically.
Logical Access Controls
MFA enforced, RBAC, quarterly access reviews.
Multi-Factor Authentication
100% coverage across all production systems.
Encryption in Transit
TLS 1.3+ enforced on all endpoints.
Encryption at Rest
AES-256 via AWS KMS, customer-managed keys available.
Intrusion Detection
AWS GuardDuty + Datadog SIEM, 24/7 alert coverage.
System Monitoring
Full observability stack, anomaly detection active.
Change Management
CAB review cadence being formalised.
Business Continuity
BCP tested Q1 2026. RTO < 4 hrs, RPO < 1 hr.
Incident Response
IR runbooks updated, tabletop exercise completed.
Availability Monitoring
99.99% SLA, real-time uptime dashboards.
Vendor Risk Management
Tier 1 vendors assessed annually, continuous monitoring.
Physical Access Controls
AWS physical controls inherited (SOC 2 Type II).
Password Policy
Complexity + rotation enforced via IdP.
Key Management
AWS KMS, 90-day key rotation, HSM-backed.
Vulnerability Management
Snyk + AWS Inspector, critical patches <48 hrs.
Privileged Access
Just-in-time access, zero standing privileges.
Built for Resilience
Globally distributed, redundant by design — your data never has a single point of failure.
Hosting Regions
AWS — multi-region active/active
Uptime SLA
Rolling 90-day window
0 %
uptime
Security Architecture
Encryption in Transit
TLS 1.3+
Encryption at Rest
AES-256
Key Management
AWS KMS
Secret Scanning
Enabled
Penetration Testing
Annual
Vulnerability Scans
Daily
Third-Party Vendors
A complete list of sub-processors with whom we share customer data, along with their certifications.
Amazon Web Services
Cloud Infrastructure
Cloud Infrastructure
All customer data
Datadog
Monitoring & Observability
Monitoring & Observability
Logs, metrics, traces
Stripe
Payment Processing
Payment Processing
Payment metadata
Intercom
Customer Support
Customer Support
Name, email, chat logs
SendGrid
Transactional Email
Transactional Email
Email address, name
MongoDB Atlas
Database
Database
Application data
Snowflake
Data Warehouse
Data Warehouse
Analytics data
Okta
Identity & SSO
Identity & SSO
User identities, auth events
Security Documentation
Public policies are immediately available. NDA-gated documents can be requested below.
Security Policy
Comprehensive information security governance, controls, and responsibilities.
Privacy Policy
How we collect, use, and protect personal data of users and customers.
Acceptable Use Policy
Rules for appropriate use of Chequr services and customer data handling.
Incident Response Plan
Procedures for detecting, responding to, and recovering from security incidents.
Penetration Test Report
Annual third-party pen test results — Cobalt.io. Critical/High: 0 open findings.
Business Continuity Plan
Disaster recovery, backup strategy, and BCP test results for continuity assurance.
Request Restricted Reports
Our penetration test reports, audit packages, and Business Continuity Plan are available under NDA. Fill in your details and we'll send a secure link within one business day.
Penetration Test Report (Q1 2026)
Cobalt.io · 0 critical open findings
SOC 2 Type II Full Report
Prescient Assurance · Dec 2025
Business Continuity Plan
Tested Mar 2026 · RTO < 4 hrs
Request Document Access
By submitting you agree to sign our standard NDA. We respond within 1 business day.
Want a Trust Center like this for your company?
Chequr builds and maintains your public Trust Center automatically — always up to date, always accurate.