Inventory. Revenue. Vendors. Supply chain. Cash flow. Cross-system failures are hiding across all of it. Sign up — your critical intelligence tabs are waiting.
Trust Center
Enterprise data deserves clear answers. This page lists what is operational today, what is in active certification, what is on our roadmap, and every third-party sub-processor that touches your data — no marketing fog.
GDPR
Operational
SOC 2 Type II
Aligned · Audit Q3 2026
AES-256
Encryption at rest
TLS 1.3
In transit
Independently verified and continuously maintained.
DuluthPath operates the full AICPA Trust Services Criteria control set (Security + Availability) with live posture monitoring. The formal Type II attestation is issued after independent CPA examination — the audit window closes Q3 2026. A live SOC 2 Readiness pack is downloadable from the Trust Center.
International standard for information security management systems (ISMS). Planned for the second half of 2026 once SOC 2 Type II is in place.
Full operational support for the EU General Data Protection Regulation. Right to access (Art. 15), erasure (Art. 17), and portability (Art. 20) are all served through live, audited endpoints — not manual ticketing.
For healthcare customers requiring Business Associate Agreements (BAA). Available on the Enterprise tier with a signed BAA; not enabled by default.
California Consumer Privacy Act compliance. Consumer rights management, data inventory, and transparent privacy practices.
FDA regulation for electronic records and electronic signatures. Targeted for life-sciences customers on the Enterprise tier; not yet validated.
Not policy language. These are live API endpoints any paying customer can use today.
Any authenticated user can download a complete JSON archive of their tenant data on demand — covering all 28 tenanted collections. Streamed, no size limits, audit-logged.
GET /api/tenant/data-exportTry it now Admin-triggered hard delete across all tenanted collections, with a signed PDF Certificate of Deletion (encrypted, non-editable) issued automatically. Retention-locked collections (invoices for tax) have PII scrubbed but aggregate totals preserved.
POST /api/admin/tenants/{id}/deleteA standard DPA conforming to GDPR Art. 28 is available to every paying customer. Sub-processor changes notified 30 days in advance via the platform notice page.
Request DPAThese are the third-party services that may process your tenant data. We notify customers 30 days in advance of any addition or change. Data residency for the underlying platform is published in the latest DPA on request.
| Sub-processor | Role | Data accessed | Location | Privacy policy |
|---|---|---|---|---|
| DuluthPath Cloud | Platform & infrastructure host | All application data (operational database, application servers, deployment artefacts) | See latest DPA — region published per customer request | View |
| Stripe | Payment processing | Billing email, card last 4, charge metadata. Full card numbers never touch DuluthPath servers. | US (Stripe Inc.) · EU (Stripe Payments Europe Ltd.) — region follows your account | View |
| Hostinger SMTP | Transactional email delivery | Recipient email + email body for invoices, alerts, and onboarding messages | EU | View |
| Anthropic (via DuluthPath AI Gateway) | AI inference (Canaan assistant, document risk analysis) | User prompts + system context excerpts. Sensitive financial figures are aggregated, not row-level. | US | View |
| Sentry | Error tracking & observability | Error stack traces with PII-scrubbed headers and bodies. Tenant ID is attached as a tag; emails/addresses are never sent. | US | View |
| PostHog | Product analytics (anonymous funnel events) | Anonymous session events + button clicks. No PII attached to events by default. | US / EU (cluster follows your account) | View |
Direct answers to the data-residency questionnaire that enterprise procurement teams typically issue. Same table is mirrored at /governance#residency.
| Question | Answer | Notes |
|---|---|---|
| Cloud provider | Google Cloud Platform (GCP) | Underlying platform infrastructure hosted on Google Cloud regions managed by our deployment partner. |
| Geographic region | United States (us-central / us-east) | EU region available on Enterprise contracts. Specific region pinning published in the customer-specific DPA on request. |
| Shared vs dedicated | Logical multi-tenant isolation | JWT-scoped tenant_id on every query · 30 tenanted collections · 23/23 leakage tests green. Dedicated single-tenant pods available on Enterprise. |
| App-server location | Same region as the database | Frontend, backend, and MongoDB all co-located in the same GCP region to keep inter-service latency under 5ms. |
| Data Processing Agreement (DPA) | Available on request | Standard DPA aligned to GDPR Art. 28 issued to every paying customer. Email Requests@duluthpath.com. |
| SOC 2 Type II | In active audit · Target Q3 2026 | Independent CPA engagement scoped. Observation period in progress. Attestation report under NDA when issued. |
| ISO 27001 | Roadmap · 2026 H2 | Gap assessment scheduled after SOC 2 Type II completes. |
| Backup frequency | Daily snapshots · 30-day retention | Point-in-time recovery available within the 30-day window. Custom retention on Enterprise. |
| Data export (GDPR Art. 20) | Self-serve, instant | Any authenticated user can download a full JSON archive of their tenant data at /billing/data-export. |
| Data deletion (GDPR Art. 17) | Hard delete with PDF certificate | Admin-triggered hard delete across 28 tenanted collections. Encrypted Certificate of Deletion (PDF, deny-all permissions) issued automatically. Retention-locked collections (invoices for tax) have PII scrubbed but aggregate totals preserved. |
Need this in a signed DPA? Email Requests@duluthpath.com.
Defense in depth across every layer of the platform.
Continuous verification that our security controls are effective.
Annual third-party penetration testing by certified ethical hackers. Findings remediated within SLA.
Continuous automated vulnerability scanning of all infrastructure and application components.
Automated SAST/DAST scanning in CI/CD pipeline. Manual code review for security-critical components.
Quarterly review of all access permissions, service accounts, and privileged access.
Tabletop exercises and simulated incident response to test readiness and communication procedures.
External audits for SOC 2, ISO 27001, and industry-specific compliance frameworks.
Your data is your data. We process it to deliver value, never to sell or share.