Trust Center
Our security posture, compliance program, and SOC 2 status — published openly for enterprise buyers, security reviewers, and procurement teams.
WatchSuit operates a continuous compliance program covering SOC 2 Type II, GDPR, CCPA / CPRA, EU AI Act, and HIPAA-aligned safeguards. We have been audited annually by an independent AICPA-accredited firm since 2025. Our SOC 2 Type II report covers the Security, Availability, and Confidentiality Trust Services Criteria. Our compliance program is built around three pillars: preventive controls (encryption, access management, secure SDLC), detective controls (audit logging, anomaly detection, posture monitoring), and responsive controls (incident response, breach notification, post-incident review).
Our most recent SOC 2 Type II report covers the calendar year ending December 31, 2025 and was issued on February 14, 2026 with an unqualified opinion. SOC 2 Type II covers a full year of operating evidence — controls such as background checks, access reviews, vulnerability scans, change management, and incident drills are tested for every quarter of the audit window.
To request a copy of our SOC 2 report, please email security@watchsuit.polsia.app. Reports are shared under NDA with active enterprise customers and qualified prospects within 3 business days.
includeSubDomains.We enforce least-privilege access via single sign-on (SSO) with MFA required for every employee. SOC 2 access reviews run quarterly; customer-data access requires a typed justification and is logged end-to-end. Production access is gated behind a hardware-security-key second factor.
Our incident response process is documented, tested quarterly, and aligned to NIST SP 800-61. WatchSuit maintains a public status page at status.watchsuit.polsia.app showing live uptime, scheduled maintenance, and ongoing incidents. Customers are notified within 24 hours of any confirmed security incident affecting their data, and within 60 days of any breach notification scenario under HIPAA § 164.404.
Our incident response policy is reviewed annually and covers roles, escalation paths, evidence preservation, customer communications, and post-incident review. The on-call rotation is staffed 24×7×365 by senior engineers with documented handover procedures.
WatchSuit runs a public responsible disclosure program. If you have found a security vulnerability or a security disclosure issue, please email security@watchsuit.polsia.app with a description of the issue and reproduction steps. We commit to acknowledging new reports within 1 business day and providing a triage within 5 business days.
Our security.txt (RFC 9116) is published at /.well-known/security.txt with our preferred contact, the disclosure expiry, and supported languages.
Our current subprocessor list — every third-party processor that touches customer data — is published at /subprocessors. We notify customers at least 30 days before adding a new subprocessor and offer a full refund of the unused subscription period for any subprocessor change you do not wish to authorize.
Production runs across multiple availability zones with automated failover. Backups run continuously with point-in-time recovery to the second; we test full restore quarterly. Recovery time objective (RTO) is 4 hours; recovery point objective (RPO) is 5 minutes for customer-scored scan data.
For security questions, vulnerability reports, or SOC 2 report requests: