Security & Compliance Overview
This page exists because enterprise InfoSec teams shouldn’t have to chase a salesperson for two weeks to learn we’re not SOC 2 Type II certified yet. Everything on the binding roadmap is dated. Everything in production today is described as in production.
Compliance posture — today vs. roadmap
The Trust-by-Design package is the single shipment to your vendor-risk team. Documents marked Today / On request are drafted, counsel-reviewed, and ship within 2 business days of an executed NDA. Documents marked In draft are finalized and ratified before pilot kickoff — we will not back-date a runbook to look ready.
On this page
Self-serve answers for vendor-risk review while our Vanta-hosted Trust Center is stood up. $ .
Why under NDA? Pre-SOC 2 organizations do not publish architecture diagrams or control narratives openly. The NDA is a standard mutual that takes ~24 hours to execute.
. SLA figures above are design targets until validated by the first DR drill and the enterprise SLA addendum is signed.
Most procurement teams start here. The SeniorCRE mutual NDA is a standard two-year, Texas-governed instrument that covers the Trust-by-Design package (SIG Lite, CAIQ, architecture diagrams, control narrative, incident response plan, and pen-test scope). Reasonable redlines are returned by counsel within one business day.
Prefer your paper? Email your standard mutual NDA to support@seniorcre.com and we’ll return redlines within one business day.
Once the NDA is executed, reply to your sponsor at SeniorCRE or contact Solutions Engineering with an introduction to your vendor-risk lead. Most Trust-by-Design packages ship within 2 business days.
Key points
- AWS us-east-1 (N. Virginia). Backups replicated to us-west-2 (Oregon).', }, { topic:
- No PHI is processed or stored outside the United States.', }, { topic: 'Tenant isolation (operator)
- AES-256 across primary data store and PHI buckets.' }, { topic: 'Encryption in transit
- TLS 1.2+ for every client, edge function, and integration endpoint.', }, { topic:
- AWS KMS with documented key rotation. A customer-managed key pathway is on the post-pilot roadmap.
- Customer-initiated deletion within 30 days per the executed DPA; sub-processor deletion verified within 90 days.
- Not yet. $ Today, customers inherit AWS SOC 2 controls for the underlying infrastructure.
- Yes. We sign Business Associate Agreements with every covered-entity customer and require BAAs from downstream sub-processors that handle PHI.
https://seniorcre.com/trust-center