Trust Center

The security posture behind the platform.

Our SOC 2 Type II report and completed questionnaires are available to your team under NDA. The rest of this page covers how we handle your data and who can touch it.

Audits & attestations

The controls we adhere to.

Where our posture is independently examined, this page says so. Where a certification is on the roadmap rather than achieved, this page says that too.

Audited & Attested
SOC 2
Annually Audited

SOC 2 Type II

Security, Availability, and Confidentiality. Twelve-month observation window. Independently audited annually by a CPA firm. Most recent issued report: April 1, 2025. Available under NDA.

HIPAA
Aligned

HIPAA

ArmorPoint’s practices are HIPAA-aligned. Alignment is not a certification, and we don’t present it as one.

On our roadmap
CMMC
Roadmap

CMMC Level 2

Working toward CMMC Level 2 (NIST SP 800-171 Rev 2). Certification requires a third-party (C3PAO) assessment, which we are actively working toward.

Status: roadmap
C3PAO assessment: planned
ISO 27001
Roadmap

ISO/IEC 27001:2022

Targeted for a future assessment cycle as part of our certification roadmap.

Status: roadmap
Within SOC 2 Audit Scope

Vulnerability management

Continuous vulnerability scanning across our environment. Independent third-party penetration testing conducted annually. Risk-based remediation per our vulnerability management policy.

Patch & configuration management

Defined patch and configuration management process.

Incident response (our own)

24/7 incident-response coverage with documented playbooks, following the SANS six-phase methodology. Containment and eradication actions require client approval.

Business continuity & DR

Failover and tabletop exercises are conducted regularly to validate business continuity and disaster recovery.

Personnel security

Background checks at hire. Mandatory annual security-awareness training. Role-based access reviews conducted periodically.

Security training: annual

Encryption in transit

Traffic to and within the platform is encrypted in transit with TLS 1.3.

These controls sit within the scope of our SOC 2 Type II audit. The report behind them is available under NDA.

Data handling

Where your data lives.

U.S. data center Operated by ArmorPoint EU data center Encrypted at rest
UNITED STATES

ArmorPoint operates a dedicated, U.S.-based, access-restricted data center. It’s built for reliability and security, with redundant power and cooling, early fire detection and suppression, and 24/7 physical security including video surveillance, controlled entry, and escorted visitor access.

Operated by
ArmorPoint
Access
Restricted
Physical security
24/7 on-site
Power & cooling
Redundant
EUROPEAN UNION

EU customer data is stored and encrypted at rest in an EU-based, ISO 27001-certified data center, with 24/7 on-site security, biometric access control, and redundant power and cooling.

Operated by
ISO 27001-certified facility
Access
Biometric
Physical security
24/7 on-site
Power & cooling
Redundant
WHO CAN TOUCH IT

U.S.-based SOC. MFA on every access.

ArmorPoint’s SOC is U.S.-based and operates 24/7/365. Access to customer environments requires MFA and is logged and monitored.

TENANT ISOLATION

Logically isolated.

Customer environments are logically isolated per tenant.

DATA RETENTION

Per the agreement you sign.

Security alerts, incidents, vulnerabilities, and tickets are retained 365 days, online and searchable. Raw event logs not tied to those records are retained 30 days online and 365 days archived and retrievable. Custom retention is available in your order form.

Alerts & incidents
365 days searchable
Raw event logs
30 days · 365 archived
Available under NDA

Documents your security team can request.

Request them through your partner contact or your ArmorPoint account team.

Available

SOC 2 Type II Report

Most-recent issued SOC 2 Type II report covering Security, Availability, and Confidentiality. Includes management response. An updated report is expected; this page will reflect it when issued.

Available

BAA template (HIPAA)

Standing Business Associate Agreement template, ready for execution.

Available

Security questionnaire (CAIQ-style)

We complete security questionnaires (SIG, VSA, and CAIQ-style) on request.

Security & vulnerability disclosure
[email protected]
System status
status.armorpoint.com

Information current as of 7/10/2026; subject to change. The controlling terms are those in your executed agreement.