Skip to main content
Trust & Security

Compliance & certifications

How Inseo approaches security, privacy, and regulatory compliance.

Effective date: January 1, 2025

1. Certifications & Compliance Status

SOC 2 Type II

We maintain SOC 2 Type II certification, demonstrating our commitment to security, availability, processing integrity, confidentiality, and privacy. Valid through December 2025.

ISO 27001

Our information security management system meets the international standard for managing sensitive company and customer information. Valid through March 2026.

GDPR & CCPA

We adhere to European Union General Data Protection Regulation and California Consumer Privacy Act requirements for data privacy, transparency, and consumer rights.

PCI DSS Level 1

Payment Card Industry Data Security Standard compliance for secure handling of credit card information. Valid through June 2025.

HIPAA

We meet Health Insurance Portability and Accountability Act requirements for handling protected health information where applicable to our services.

2. Security Frameworks

NIST Cybersecurity Framework

We align our security practices with the NIST framework across Identify, Protect, Detect, Respond, and Recover functions.

OWASP Security Standards

Our web application security practices follow OWASP guidelines including Top 10 coverage, secure coding, testing, and code review.

CIS Controls

We implement Center for Internet Security Controls for asset management, access control, data protection, and incident response.

3. Audit History

SOC 2 Type II Audit

Deloitte & Touche LLP — December 2024, clean opinion. Next audit: December 2025.

ISO 27001 Surveillance Audit

BSI Group — September 2024, no non-conformities. Next audit: September 2025.

PCI DSS Assessment

Trustwave — June 2024, compliant. Next audit: June 2025.

Internal Security Audit

Internal audit team — monthly ongoing compliance monitoring.

4. Governance Policies

Information Security Policy

Comprehensive framework for protecting information assets and maintaining security standards. Last updated January 2025.

Data Privacy Policy

Guidelines for collecting, processing, and protecting personal data in compliance with privacy regulations. Last updated January 2025.

Incident Response Policy

Procedures for detecting, responding to, and recovering from security incidents and data breaches. Last updated December 2024.

Business Continuity & Vendor Management

Framework for maintaining operations during disruptions and standards for evaluating third-party vendors. Updated Q4 2024.

Need Compliance Documentation?

Request SOC reports, DPA copies, or security questionnaires for your vendor review.