ThinkGRC™ Trust Center

Enterprise-Grade Security.
Complete Data Sovereignty.

Your trust is our most critical governance asset. Every architectural decision in ThinkGRC™ is made with security, privacy, and regulatory compliance as first principles — not afterthoughts.

All systems operational

Live Compliance & Resilience Metrics

Certifications & Compliance

SOC 2 Type II

Annual third-party audit of security, availability, and confidentiality controls.

ISO 27001:2022

Internationally recognised information security management standard.

GDPR Compliant

Full EU/UK GDPR data protection compliance with DPA on request.

Cyber Essentials+

UK government-backed scheme protecting against common cyber attacks.

Security Architecture

Zero-Trust Architecture
  • Least-privilege access enforcement
  • Role-based access control (RBAC) on all entities
  • End-to-end TLS 1.3 encryption in transit
  • AES-256 encryption at rest
  • Immutable audit trails
Continuous Monitoring
  • 24/7 infrastructure monitoring
  • Real-time anomaly detection
  • Automated threat response
  • Vulnerability scanning on every deployment
  • Penetration testing (biannual)
Infrastructure & Availability
  • 99.9% uptime SLA (Enterprise)
  • Multi-region redundancy
  • Automated failover & circuit breakers
  • Daily encrypted backups with 30-day retention
  • Disaster recovery RTO < 4 hours
Identity & Access
  • Multi-factor authentication (MFA)
  • Single Sign-On (SSO) via SAML 2.0 / OIDC
  • Session management & forced logout
  • IP allowlisting (Enterprise)
  • User activity logging on all actions

Data Residency Options

Choose where your data lives to satisfy local regulatory requirements. Data never leaves your selected region without explicit consent.

🇪🇺EU West
🇬🇧UK South
🇺🇸US East
🇸🇦ME Central
🌏AP Southeast
🏢On-PremiseEnterprise

Data & Privacy FAQ

Legal & Governance Documents

Compliance Document Vault

v1.0 · Founder Approved

Enterprise procurement portal for due diligence and customer onboarding. Public governance documents are available for immediate viewing. Restricted compliance artifacts require authenticated access request — every access attempt is logged to an immutable audit trail.

Compliance Document Vault
Authenticated procurement portal — all access requests are logged to an immutable audit trail
SOC 2 Type II Report
RESTRICTED · AICPA

Independent third-party audit of security, availability, processing integrity, confidentiality, and privacy controls.

External Penetration Test Summary
RESTRICTED · CREST / PTES

Executive summary of our most recent biannual penetration test conducted by a CREST-accredited third party.

Data Processing Addendum (DPA)
CONFIDENTIAL · GDPR Art. 28

Our standard GDPR-compliant Data Processing Agreement governing how we handle personal data on your behalf.

ISO 27001:2022 Certificate
INTERNAL · ISO/IEC 27001:2022

Current certification confirming our Information Security Management System meets ISO/IEC 27001:2022 requirements.

Cyber Essentials Plus Certificate
INTERNAL · UK NCSC

UK NCSC Cyber Essentials Plus certification demonstrating our baseline cyber hygiene controls.

Signed URLs expire after 15 minutes. RESTRICTED requires executive approval · CONFIDENTIAL requires NDA · INTERNAL requires authentication only.
Trust Center Documents v1.0
Founder-approved baseline governance documents — open access, no request required. Updated as procurement feedback is received.
Security Overview
PUBLIC · v1.0 · NIST / ISO 27001

Platform security posture: authentication, encryption, data isolation, audit logging, and access control architecture.

Privacy & Data Processing Statement
PUBLIC · v1.0 · GDPR / UK DPA 2018

How customer data is handled: ownership, retention, deletion, subprocessors, and AI usage policy.

Customer Onboarding Guide
PUBLIC · v1.0 · ThinkGRC™ Operations

Step-by-step guide for provisioning your workspace, inviting users, importing data, and conducting your first compliance review.

Support & SLA Guide
PUBLIC · v1.0 · ThinkGRC™ Operations

Support channels, response times, severity classifications, and escalation process for ThinkGRC customers.

Security Enquiries & DPA Requests

For penetration test reports, DPA requests, vendor security questionnaires, or specific compliance queries, our security team responds within 2 business days.

We Value Your Privacy

We use cookies to enhance your experience, analyze site traffic, and personalize content. By clicking "Accept All," you consent to our use of cookies. You can customize your preferences or learn more in our Cookie Policy.