Compliance & certifications
How Inseo approaches security, privacy, and regulatory compliance.
1. Certifications & Compliance Status
SOC 2 Type II
We maintain SOC 2 Type II certification, demonstrating our commitment to security, availability, processing integrity, confidentiality, and privacy. Valid through December 2025.
ISO 27001
Our information security management system meets the international standard for managing sensitive company and customer information. Valid through March 2026.
GDPR & CCPA
We adhere to European Union General Data Protection Regulation and California Consumer Privacy Act requirements for data privacy, transparency, and consumer rights.
PCI DSS Level 1
Payment Card Industry Data Security Standard compliance for secure handling of credit card information. Valid through June 2025.
HIPAA
We meet Health Insurance Portability and Accountability Act requirements for handling protected health information where applicable to our services.
2. Security Frameworks
NIST Cybersecurity Framework
We align our security practices with the NIST framework across Identify, Protect, Detect, Respond, and Recover functions.
OWASP Security Standards
Our web application security practices follow OWASP guidelines including Top 10 coverage, secure coding, testing, and code review.
CIS Controls
We implement Center for Internet Security Controls for asset management, access control, data protection, and incident response.
3. Audit History
SOC 2 Type II Audit
Deloitte & Touche LLP — December 2024, clean opinion. Next audit: December 2025.
ISO 27001 Surveillance Audit
BSI Group — September 2024, no non-conformities. Next audit: September 2025.
PCI DSS Assessment
Trustwave — June 2024, compliant. Next audit: June 2025.
Internal Security Audit
Internal audit team — monthly ongoing compliance monitoring.
4. Governance Policies
Information Security Policy
Comprehensive framework for protecting information assets and maintaining security standards. Last updated January 2025.
Data Privacy Policy
Guidelines for collecting, processing, and protecting personal data in compliance with privacy regulations. Last updated January 2025.
Incident Response Policy
Procedures for detecting, responding to, and recovering from security incidents and data breaches. Last updated December 2024.
Business Continuity & Vendor Management
Framework for maintaining operations during disruptions and standards for evaluating third-party vendors. Updated Q4 2024.
Need Compliance Documentation?
Request SOC reports, DPA copies, or security questionnaires for your vendor review.