SecurePoint USA
Trust Center
Everything a security or procurement reviewer needs, in one place. We answer certification questions directly and do not claim a certification unless we can hand you the signed report.
Last reviewed: September 1, 2026
Certifications and program status
| Framework | Status | Detail |
|---|---|---|
| SOC 2 Type II | Not yet certified | Tentative Q3 2027 target. Controls are mapped today; the report does not exist yet. |
| CMMC 2.0 Level 2 | Self-assessment posture | Controls implemented; no certification is claimed. Phase 1 self-assessment is in force; DoD suspended Phase 2 on July 13, 2026 pending review. |
| NIST SP 800-171 | Rev 2 under DFARS 252.204-7012 | A DoD class deviation keeps contracts on Rev 2; Rev 3 is tracked. |
| FedRAMP | Not claimed | No Ready, Authorized, or certified status is claimed. |
| ISO/IEC 27001 | Not certified | Not currently pursued as a certification. |
| Third-party penetration test | Planned | Internal security review is ongoing; a formal third-party test has not yet been completed. |
Regulatory dates move. Verify CMMC status at dodcio.defense.gov and DFARS clause status at acquisition.gov before relying on a date.
Availability and incident response
The platform runs on Vercel and Supabase in United States regions. We do not currently publish a public uptime SLA; service-level terms are set in the customer agreement. Internal service-level objectives, error budgets, and monitoring runbooks exist and are available for review during procurement.
Incident response follows a documented runbook with named roles (incident commander, communications, security engineering, customer liaison). Notification commitments depend on contract and jurisdiction and are set in the agreement rather than promised here.
Documents
Security
- Security Center
Architecture, isolation, identity, encryption, audit logging, and downloadable evidence
- Vulnerability disclosure
How to report an issue and what we commit to
- security.txt
Machine-readable security contact (RFC 9116)
- Security & compliance summary
Plain-language overview for IT leadership
Data and privacy
- Privacy Policy
Including the data location commitment and retention
- Data Processing Agreement
GDPR Article 28 terms for customers that need them
- Subprocessors
Who processes customer data on our behalf, and when
- ID scan privacy notice
What happens to an identity document captured at check-in
Terms
- Terms of Service
Commercial terms
- AI compliance statement
Where AI assists and where a person decides
Due diligence
A downloadable security packet, control matrix, evidence map, and subprocessor list are on the Security Center. For questionnaires, an NDA for deeper review, or an architecture call with engineering, write to security@securepointusa.com.