The security posture behind the platform.
Our SOC 2 Type II report and completed questionnaires are available to your team under NDA. The rest of this page covers how we handle your data and who can touch it.
Most-recent issued report covering Security, Availability, and Confidentiality. Includes management response.
The controls we adhere to.
Where our posture is independently examined, this page says so. Where a certification is on the roadmap rather than achieved, this page says that too.
SOC 2 Type II
Security, Availability, and Confidentiality. Twelve-month observation window. Independently audited annually by a CPA firm. Most recent issued report: April 1, 2025. Available under NDA.
HIPAA
ArmorPoint’s practices are HIPAA-aligned. Alignment is not a certification, and we don’t present it as one.
CMMC Level 2
Working toward CMMC Level 2 (NIST SP 800-171 Rev 2). Certification requires a third-party (C3PAO) assessment, which we are actively working toward.
C3PAO assessment: planned
ISO/IEC 27001:2022
Targeted for a future assessment cycle as part of our certification roadmap.
Vulnerability management
Continuous vulnerability scanning across our environment. Independent third-party penetration testing conducted annually. Risk-based remediation per our vulnerability management policy.
Patch & configuration management
Defined patch and configuration management process.
Incident response (our own)
24/7 incident-response coverage with documented playbooks, following the SANS six-phase methodology. Containment and eradication actions require client approval.
Business continuity & DR
Failover and tabletop exercises are conducted regularly to validate business continuity and disaster recovery.
Personnel security
Background checks at hire. Mandatory annual security-awareness training. Role-based access reviews conducted periodically.
Encryption in transit
Traffic to and within the platform is encrypted in transit with TLS 1.3.
These controls sit within the scope of our SOC 2 Type II audit. The report behind them is available under NDA.
Where your data lives.
ArmorPoint operates a dedicated, U.S.-based, access-restricted data center. It’s built for reliability and security, with redundant power and cooling, early fire detection and suppression, and 24/7 physical security including video surveillance, controlled entry, and escorted visitor access.
EU customer data is stored and encrypted at rest in an EU-based, ISO 27001-certified data center, with 24/7 on-site security, biometric access control, and redundant power and cooling.
U.S.-based SOC. MFA on every access.
ArmorPoint’s SOC is U.S.-based and operates 24/7/365. Access to customer environments requires MFA and is logged and monitored.
Logically isolated.
Customer environments are logically isolated per tenant.
Per the agreement you sign.
Security alerts, incidents, vulnerabilities, and tickets are retained 365 days, online and searchable. Raw event logs not tied to those records are retained 30 days online and 365 days archived and retrievable. Custom retention is available in your order form.
Documents your security team can request.
Request them through your partner contact or your ArmorPoint account team.
SOC 2 Type II Report
Most-recent issued SOC 2 Type II report covering Security, Availability, and Confidentiality. Includes management response. An updated report is expected; this page will reflect it when issued.
BAA template (HIPAA)
Standing Business Associate Agreement template, ready for execution.
Security questionnaire (CAIQ-style)
We complete security questionnaires (SIG, VSA, and CAIQ-style) on request.
Information current as of 7/10/2026; subject to change. The controlling terms are those in your executed agreement.