At Incluud®, trust is the foundation of every partnership. Our security posture is built to earn and maintain that trust, protecting our systems and your data with industry-leading practices and a proactive, continuous-improvement mindset. This is a high-level overview of our program.
We designed our security program around established standards to ensure a comprehensive and defensible posture across our data, systems, and AI.
We leverage the NIST SP 800-53 Rev. 5 control catalog to guide our security policies and procedures, and run quarterly risk assessments aligned to the NIST Risk Management Framework.
Currently finalizing our SOC 2 Type 2 audit.
For our AI-driven systems, we use the NIST AI Risk Management Framework to govern development, emphasizing transparency, robustness, and accountability to mitigate bias and ensure model integrity.
Our services are built and hosted on Microsoft Azure, whose certifications, including FedRAMP and ISO 27001, attest to the security of the underlying infrastructure. We layer our own controls on top.
Microsoft Defender for Cloud and Azure Sentinel actively monitor for and respond to security events across the environment.
Data is encrypted in transit and at rest, with least-privilege access controls and strict authentication procedures.
All company devices enforce hardening standards, automated patching, and EDR/XDR protection through centralized management.
Development, staging, and production are isolated, with audit logging across platform access for full oversight.
Our Information Security Policy mandates secure data handling and disposal, reinforced by monthly security-awareness training.
Quarterly NIST-aligned risk assessments plus third-party audits and penetration testing validate our controls over time.
Our privacy and security practices are consolidated into a single, authoritative source of truth, defining governance, roles, and accountability, with ready-to-use playbooks and auditable evidence of program execution.
Data protection is embedded throughout product development and business processes, not bolted on at the end.
Clear ownership, documentation, and reporting for every privacy and security control we operate.
Documented procedures for incident response, vendor management, data-subject requests, and regulatory reporting.
Practices support compliance with applicable laws and contracts, including HIPAA security practices and GDPR/CCPA obligations.
If a security incident occurs, we act quickly, follow applicable law, and prioritize clear communication, notifying account super-administrators in line with regulatory and contractual timelines:
We vet every sub-processor through a rigorous process and monitor them on an ongoing basis:
We're happy to share a detailed overview of our security program under NDA, and to answer diligence questionnaires. Reach out and our team will follow up.