SuitePortal

Compliance

SuitePortal's compliance posture and certifications.

Compliance

This documentation is currently being developed. Check back soon for complete content.

Overview

SuitePortal is designed with security and compliance as foundational requirements.

Compliance Framework

SOC 2

SuitePortal is working toward SOC 2 Type II certification.

Trust Service Criteria:

  • Security
  • Availability
  • Confidentiality

GDPR

SuitePortal supports GDPR compliance:

  • Data processing agreements
  • Right to erasure support
  • Data portability
  • Privacy by design

Security Controls

Technical Controls

  • Encryption at rest and in transit
  • Access controls
  • Audit logging
  • Vulnerability management

Administrative Controls

  • Security policies
  • Employee training
  • Vendor management
  • Incident response

Physical Controls

  • Cloud provider security (AWS/Vercel)
  • Data center certifications

Vendor Risk Assessment

For vendor risk questionnaires, contact: trey@suiteportal.io

Common Questions

TopicResponse
Data locationUS (configurable for enterprise)
EncryptionAES-256 at rest, TLS 1.2+ in transit
Backup frequencyDaily
RetentionConfigurable