Skip to main content

Inventory. Revenue. Vendors. Supply chain. Cash flow. Cross-system failures are hiding across all of it. Sign up — your critical intelligence tabs are waiting.

Trust Center

Security & Compliance

Enterprise data deserves clear answers. This page lists what is operational today, what is in active certification, what is on our roadmap, and every third-party sub-processor that touches your data — no marketing fog.

GDPR

Operational

SOC 2 Type II

Aligned · Audit Q3 2026

AES-256

Encryption at rest

TLS 1.3

In transit

Certifications & Compliance

Independently verified and continuously maintained.

SOC 2 Type II

Aligned · Audit window Q3 2026

DuluthPath operates the full AICPA Trust Services Criteria control set (Security + Availability) with live posture monitoring. The formal Type II attestation is issued after independent CPA examination — the audit window closes Q3 2026. A live SOC 2 Readiness pack is downloadable from the Trust Center.

24 controls operating across CC1–CC9 + A1.1–A1.5
Live control status at /trust
Readiness pack (PDF) available on request
Attestation report available under NDA when issued

ISO 27001

Roadmap · 2026 H2

International standard for information security management systems (ISMS). Planned for the second half of 2026 once SOC 2 Type II is in place.

Gap assessment scheduled
ISMS scope under definition
Targeted certification by end of 2026

GDPR

Operational

Full operational support for the EU General Data Protection Regulation. Right to access (Art. 15), erasure (Art. 17), and portability (Art. 20) are all served through live, audited endpoints — not manual ticketing.

Self-serve tenant data export (Art. 20)
Admin-triggered tenant deletion with PDF certificate (Art. 17)
Hashed-IP visitor logs · no raw PII at rest

HIPAA

On Request

For healthcare customers requiring Business Associate Agreements (BAA). Available on the Enterprise tier with a signed BAA; not enabled by default.

Business Associate Agreement (BAA) available on Enterprise
PHI encrypted at rest and in transit
Access controls and audit trails for all PHI

CCPA

Operational

California Consumer Privacy Act compliance. Consumer rights management, data inventory, and transparent privacy practices.

Consumer right to know, delete, and opt-out
Data inventory and mapping maintained
Annual privacy impact assessments

21 CFR Part 11

Roadmap

FDA regulation for electronic records and electronic signatures. Targeted for life-sciences customers on the Enterprise tier; not yet validated.

Validation pack planned for Enterprise
Electronic signature workflows in design
Audit trail surface already in place

Your Data Rights — Live Endpoints

Not policy language. These are live API endpoints any paying customer can use today.

Data Portability (GDPR Art. 20)

Any authenticated user can download a complete JSON archive of their tenant data on demand — covering all 28 tenanted collections. Streamed, no size limits, audit-logged.

GET /api/tenant/data-exportTry it now

Right to Erasure (GDPR Art. 17)

Admin-triggered hard delete across all tenanted collections, with a signed PDF Certificate of Deletion (encrypted, non-editable) issued automatically. Retention-locked collections (invoices for tax) have PII scrubbed but aggregate totals preserved.

POST /api/admin/tenants/{id}/delete

Data Processing Agreement (DPA)

A standard DPA conforming to GDPR Art. 28 is available to every paying customer. Sub-processor changes notified 30 days in advance via the platform notice page.

Request DPA

Sub-processors

These are the third-party services that may process your tenant data. We notify customers 30 days in advance of any addition or change. Data residency for the underlying platform is published in the latest DPA on request.

Sub-processorRoleData accessedLocationPrivacy policy
DuluthPath CloudPlatform & infrastructure hostAll application data (operational database, application servers, deployment artefacts)See latest DPA — region published per customer requestView
StripePayment processingBilling email, card last 4, charge metadata. Full card numbers never touch DuluthPath servers.US (Stripe Inc.) · EU (Stripe Payments Europe Ltd.) — region follows your accountView
Hostinger SMTPTransactional email deliveryRecipient email + email body for invoices, alerts, and onboarding messagesEUView
Anthropic (via DuluthPath AI Gateway)AI inference (Canaan assistant, document risk analysis)User prompts + system context excerpts. Sensitive financial figures are aggregated, not row-level.USView
SentryError tracking & observabilityError stack traces with PII-scrubbed headers and bodies. Tenant ID is attached as a tag; emails/addresses are never sent.USView
PostHogProduct analytics (anonymous funnel events)Anonymous session events + button clicks. No PII attached to events by default.US / EU (cluster follows your account)View

Hosting & Data Residency

Direct answers to the data-residency questionnaire that enterprise procurement teams typically issue. Same table is mirrored at /governance#residency.

QuestionAnswerNotes
Cloud providerGoogle Cloud Platform (GCP)Underlying platform infrastructure hosted on Google Cloud regions managed by our deployment partner.
Geographic regionUnited States (us-central / us-east)EU region available on Enterprise contracts. Specific region pinning published in the customer-specific DPA on request.
Shared vs dedicatedLogical multi-tenant isolationJWT-scoped tenant_id on every query · 30 tenanted collections · 23/23 leakage tests green. Dedicated single-tenant pods available on Enterprise.
App-server locationSame region as the databaseFrontend, backend, and MongoDB all co-located in the same GCP region to keep inter-service latency under 5ms.
Data Processing Agreement (DPA)Available on requestStandard DPA aligned to GDPR Art. 28 issued to every paying customer. Email Requests@duluthpath.com.
SOC 2 Type IIIn active audit · Target Q3 2026Independent CPA engagement scoped. Observation period in progress. Attestation report under NDA when issued.
ISO 27001Roadmap · 2026 H2Gap assessment scheduled after SOC 2 Type II completes.
Backup frequencyDaily snapshots · 30-day retentionPoint-in-time recovery available within the 30-day window. Custom retention on Enterprise.
Data export (GDPR Art. 20)Self-serve, instantAny authenticated user can download a full JSON archive of their tenant data at /billing/data-export.
Data deletion (GDPR Art. 17)Hard delete with PDF certificateAdmin-triggered hard delete across 28 tenanted collections. Encrypted Certificate of Deletion (PDF, deny-all permissions) issued automatically. Retention-locked collections (invoices for tax) have PII scrubbed but aggregate totals preserved.

Need this in a signed DPA? Email Requests@duluthpath.com.

Security Architecture

Defense in depth across every layer of the platform.

Encryption

Data at RestAES-256 encryption
Data in TransitTLS 1.3
Key ManagementAzure Key Vault / AWS KMS
Database EncryptionTransparent Data Encryption (TDE)

Authentication & Access

AuthenticationOAuth 2.0, JWT, SAML 2.0
MFAMulti-factor authentication enforced
RBACRole-based access control
SSOAzure AD, Okta, OneLogin integration

Infrastructure

HostingAzure / AWS enterprise-grade
Availability99.99% SLA uptime
RegionsUS, EU, APAC deployment options
DDoS ProtectionAzure DDoS / AWS Shield

Data Protection

BackupContinuous backup with point-in-time recovery
DRCross-region disaster recovery (RPO < 1 hr)
RetentionConfigurable data retention policies
DeletionCryptographic erasure on request

Auditing & Testing

Continuous verification that our security controls are effective.

Penetration Testing

Annual

Annual third-party penetration testing by certified ethical hackers. Findings remediated within SLA.

Vulnerability Scanning

Continuous

Continuous automated vulnerability scanning of all infrastructure and application components.

Code Security Review

Every Deploy

Automated SAST/DAST scanning in CI/CD pipeline. Manual code review for security-critical components.

Access Reviews

Quarterly

Quarterly review of all access permissions, service accounts, and privileged access.

Incident Response Drills

Semi-Annual

Tabletop exercises and simulated incident response to test readiness and communication procedures.

Compliance Audits

Annual

External audits for SOC 2, ISO 27001, and industry-specific compliance frameworks.

Responsible Data Handling

Your data is your data. We process it to deliver value, never to sell or share.

Your Data, Your Control

You own all data processed through DuluthPath
Full data export at any time in standard formats
Data deleted within 30 days of contract termination
No data used for model training without consent

Incident Response

24/7 security operations center (SOC)
Incident notification within 72 hours (GDPR)
Documented incident response playbook
Post-incident review and remediation

Data Residency

Choose data processing region (US, EU, APAC)
Data never leaves your selected region
Sub-processor transparency and oversight
Standard Contractual Clauses for cross-border

Need compliance documentation?

Request our SOC 2 Type II report, security questionnaire responses, or schedule a security review with our team.