Compliance
SuitePortal's compliance posture and certifications.
Compliance
This documentation is currently being developed. Check back soon for complete content.
Overview
SuitePortal is designed with security and compliance as foundational requirements.
Compliance Framework
SOC 2
SuitePortal is working toward SOC 2 Type II certification.
Trust Service Criteria:
- Security
- Availability
- Confidentiality
GDPR
SuitePortal supports GDPR compliance:
- Data processing agreements
- Right to erasure support
- Data portability
- Privacy by design
Security Controls
Technical Controls
- Encryption at rest and in transit
- Access controls
- Audit logging
- Vulnerability management
Administrative Controls
- Security policies
- Employee training
- Vendor management
- Incident response
Physical Controls
- Cloud provider security (AWS/Vercel)
- Data center certifications
Vendor Risk Assessment
For vendor risk questionnaires, contact: trey@suiteportal.io
Common Questions
| Topic | Response |
|---|---|
| Data location | US (configurable for enterprise) |
| Encryption | AES-256 at rest, TLS 1.2+ in transit |
| Backup frequency | Daily |
| Retention | Configurable |