SecurePoint USA
Trust Center
Everything a security or procurement reviewer needs, in one place.
Last reviewed: September 1, 2026
Certifications and program status
| Framework | Status | Detail |
|---|---|---|
| SOC 2 Type II | Not certified. Target Q3 2027 | Controls mapped to the Trust Services Criteria. Audit engagement in progress; scope and observation period are still being set, so the target date is not a commitment. |
| CMMC 2.0 Level 2 | Controls implemented; Level 2 self-assessment posture | No C3PAO certification is claimed. Phase 1 self-assessment is in force; DoD suspended Phase 2 on July 13, 2026 pending review. |
| NIST SP 800-171 | Rev 2 under DFARS 252.204-7012 | A DoD class deviation keeps contracts on Rev 2; Rev 3 is tracked. |
| FedRAMP | Not claimed | No Ready, Authorized, or certified status is claimed. |
| ISO/IEC 27001 | Control-informed; no audit planned | Used as a rubric for our own program. We are not pursuing certification. |
| Third-party penetration test | Planned | Internal security review is ongoing. Contact us for current timelines. |
Availability and incident response
The platform runs on Vercel and Supabase in United States regions. Service-level terms are set in the customer agreement. Internal service-level objectives, error budgets, and monitoring runbooks are available for review during procurement.
Incident response follows a documented runbook with named roles: incident commander, communications, security engineering, and customer liaison. Notification commitments are set in the customer agreement and vary by contract and jurisdiction.
Documents
Security
- Security Center
Architecture, isolation, identity, encryption, audit logging, and downloadable evidence
- Vulnerability disclosure
How to report an issue and what we commit to
- security.txt
Machine-readable security contact (RFC 9116)
- Security & compliance summary
Plain-language overview for IT leadership
Data and privacy
- Privacy Policy
Including the data location commitment and retention
- Data Processing Agreement
GDPR Article 28 terms for customers that need them
- Subprocessors
Who processes customer data on our behalf, and when
- ID scan privacy notice
What happens to an identity document captured at check-in
Terms
- Terms of Service
Commercial terms
- AI compliance statement
Where AI assists and where a person decides
Due diligence
A downloadable security packet, control matrix, evidence map, and subprocessor list are on the Security Center. For questionnaires, an NDA for deeper review, or an architecture call with engineering, write to security@securepointusa.com.