Trust Center
This page exists because enterprise InfoSec teams shouldn’t have to chase a salesperson for two weeks to learn what state a control is actually in. Every fact below renders at the lowest state our record supports.
Compliance posture — today vs. roadmap
The Trust-by-Design package is the single shipment to your vendor-risk team. Documents marked Today / On request are drafted, counsel-reviewed, and ship within 2 business days of an executed NDA. Documents marked In draft are finalized and ratified before pilot kickoff — we will not back-date a runbook to look ready.
On this page
SeniorCRE asks operators to govern what is true. We hold ourselves to the same standard. This page states what exists today, what has been exercised, what has been independently tested, what remains underway, and what we do not claim.
Why under NDA? Pre-SOC 2 organizations do not publish architecture diagrams or control narratives openly. The NDA is a standard mutual that takes ~24 hours to execute.
. SLA figures above are design targets until validated by the first DR drill and the enterprise SLA addendum is signed.
Most procurement teams start here. The SeniorCRE mutual NDA is a standard two-year, Texas-governed instrument that covers the Trust-by-Design package (SIG Lite, CAIQ, architecture diagrams, control narrative, incident response plan, and pen-test scope). Reasonable redlines are returned by counsel within one business day.
Prefer your paper? Email your standard mutual NDA to support@seniorcre.com and we’ll return redlines within one business day.
Once the NDA is executed, reply to your sponsor at SeniorCRE or contact Solutions Engineering with an introduction to your vendor-risk lead. Most Trust-by-Design packages ship within 2 business days.
Key points
- AWS KMS with documented key rotation. A customer-managed key pathway is on the post-pilot roadmap.
- Customer-initiated deletion within 30 days per the executed DPA; sub-processor deletion verified within 90 days.
- Not yet. $ Today, customers inherit AWS SOC 2 controls for the underlying infrastructure.
- Yes. We sign Business Associate Agreements with every covered-entity customer and require BAAs from downstream sub-processors that handle PHI.
- Yes. SSO (SAML 2.0) for enterprise tier; mandatory phone-based MFA for all administrative roles; session timeout and concurrent-session limits enforced.
- AWS us-east-1 with encrypted backups to us-west-2. No PHI processed or stored outside the United States.
- Per the HIPAA Breach Notification Rule (no later than 60 days from discovery). Sub-processor incidents are cascaded within the same window. Our incident-response runbook is evolving toward a faster best-effort notification target.
- Yes. Operators own their data and can export the full canonical model on demand. Termination triggers a 30-day export window followed by verified deletion.
Frequently asked questions
- Are you SOC 2 certified?
- Not yet. $ Today, customers inherit AWS SOC 2 controls for the underlying infrastructure.
- Will you sign our BAA?
- Yes. We sign Business Associate Agreements with every covered-entity customer and require BAAs from downstream sub-processors that handle PHI.
- Do you support SSO and MFA?
- Yes. SSO (SAML 2.0) for enterprise tier; mandatory phone-based MFA for all administrative roles; session timeout and concurrent-session limits enforced.
- Where is data stored?
- AWS us-east-1 with encrypted backups to us-west-2. No PHI processed or stored outside the United States.
- How do we receive incident notifications?
- Per the HIPAA Breach Notification Rule (no later than 60 days from discovery). Sub-processor incidents are cascaded within the same window. Our incident-response runbook is evolving toward a faster best-effort notification target.
- Can we export our data?
- Yes. Operators own their data and can export the full canonical model on demand. Termination triggers a 30-day export window followed by verified deletion.
https://seniorcre.com/trust