Trust Center

The security posture behind the platform.

Our SOC 2 Type II report and completed questionnaires are available to your team under NDA. The rest of this page covers how we handle your data and who can touch it.

Audits & attestations

The controls we adhere to.

Where our posture is independently examined, this page says so. Where a certification is on the roadmap rather than achieved, this page says that too.

Audited & Attested
SOC 2
Annually Audited

SOC 2 Type II

Security, Availability, and Confidentiality. Twelve-month observation window. Independently audited annually by a CPA firm. Most recent issued report covers March 1 2025 through February 28 2026. Available under NDA.

HIPAA
Aligned

HIPAA

ArmorPoint’s practices are HIPAA-aligned, and an independent HIPAA Security Rule assessment covering March 1 2025 through February 28 2026 is available under NDA. Alignment is not a certification, and we don’t present it as one.

On our roadmap
CMMC
Roadmap

CMMC Level 2

Working toward CMMC Level 2 (NIST SP 800-171 Rev 2). Certification requires a third-party (C3PAO) assessment, which we are actively working toward.

Status: roadmap
C3PAO assessment: planned
ISO 27001
Roadmap

ISO/IEC 27001:2022

Targeted for a future assessment cycle as part of our certification roadmap.

Status: roadmap
Within SOC 2 Audit Scope

Vulnerability management

Continuous vulnerability scanning across our environment. Independent third-party penetration testing conducted annually. Risk-based remediation per our vulnerability management policy.

Patch & configuration management

Defined patch and configuration management process.

Incident response (our own)

Round-the-clock incident-response coverage for ArmorPoint’s own environment, with documented playbooks following the SANS six-phase methodology. Where our response would reach into a client environment, containment and eradication actions require that client’s approval. Response authority for the managed SOC service is set by your service agreement.

Business continuity & DR

Failover and tabletop exercises are conducted regularly to validate business continuity and disaster recovery.

Personnel security

Background checks at hire. Mandatory annual security-awareness training. Role-based access reviews conducted periodically.

Security training: annual

Encryption in transit

Traffic to and within the platform is encrypted in transit with TLS 1.3.

These controls sit within the scope of our SOC 2 Type II audit. The report behind them is available under NDA.

Data handling

Where your data lives.

U.S. data center Operated by ArmorPoint EU data center Encrypted at rest
UNITED STATES

ArmorPoint operates a dedicated, U.S.-based, access-restricted data center. It’s built for reliability and security, with redundant power and cooling, early fire detection and suppression, and 24/7 physical security including video surveillance, controlled entry, and escorted visitor access.

Operated by
ArmorPoint
Access
Restricted
Physical security
24/7 on-site
Power & cooling
Redundant
EUROPEAN UNION

EU customer data is stored and encrypted at rest in an EU-based, ISO 27001-certified data center, with 24/7 on-site security, biometric access control, and redundant power and cooling.

Operated by
ISO 27001-certified facility
Access
Biometric
Physical security
24/7 on-site
Power & cooling
Redundant
WHO CAN TOUCH IT

U.S.-based SOC. MFA on every access.

ArmorPoint’s SOC is U.S.-based and operates 24/7/365. Access to customer environments requires MFA and is logged and monitored.

TENANT ISOLATION

Logically isolated.

Customer environments are logically isolated per tenant.

DATA RETENTION

Per the agreement you sign.

Security alerts, incidents, vulnerabilities, and tickets are retained 365 days, online and searchable. Raw event logs not tied to those records are retained 30 days online and 365 days archived and retrievable. Custom retention is available in your order form.

Alerts & incidents
365 days searchable
Raw event logs
30 days · 365 archived
Available under NDA

Documents your security team can request.

Request them through your partner contact or your ArmorPoint account team.

Available

SOC 2 Type II Report

FY26 SOC 2 Type II report covering Security, Availability, and Confidentiality, for the period March 1 2025 through February 28 2026. Includes management response.

Available

HIPAA Security Rule assessment

Independent HIPAA Security Rule assessment covering March 1 2025 through February 28 2026, issued alongside our SOC 2 Type II report. HIPAA has no certification; this is an assessment.

Available

BAA template (HIPAA)

Standing Business Associate Agreement template, ready for execution.

Available

Security questionnaire (CAIQ-style)

We complete security questionnaires (SIG, VSA, and CAIQ-style) on request.

Security & vulnerability disclosure
[email protected]
System status
status.armorpoint.com

Information current as of 7/10/2026; subject to change. The controlling terms are those in your executed agreement.