Trust Center

Everything you need to
trust us with your data.

One place for our security posture, certifications, and the documents your vendor-review team needs — with a clear path to request anything under NDA.

Last updated April 2026
Need documents fast? Email trust@crimsontalent.com and we'll share our SOC 2 report, penetration-test summary, and DPA under NDA — usually within one business day.

Independently verified.

Our security and privacy programs are audited by third parties and mapped to the frameworks your team already trusts.

SOC 2 Type II

Independently audited by Schellman against the Security, Availability and Confidentiality Trust Services Criteria, covering a continuous observation period.

Certified

ISO/IEC 27001

Certified information-security management system (ISMS), covering risk assessment, controls, and continual improvement across the organization.

Certified

ISO/IEC 27701

Privacy Information Management System extension to 27001, formalizing how we handle personal data as both a controller and a processor.

Certified

GDPR

We honor EU data-subject rights, maintain lawful bases for processing, and offer Standard Contractual Clauses through our DPA for international transfers.

Compliant

CCPA / CPRA

California residents can exercise access, deletion and opt-out rights. Our Privacy Choices page provides self-service options.

Compliant

NIST CSF

Our security program is mapped to the NIST Cybersecurity Framework — Identify, Protect, Detect, Respond, Recover — and continuously self-assessed.

Aligned

Available documents.

Detailed evidence for your vendor-security review. Most items require a signed NDA; the subprocessor list is public.

SOC 2 Type II report
Full independent audit report from Schellman, including controls and test results.
Under NDA
Penetration-test summary
Executive summary of our most recent third-party penetration test and remediation.
Under NDA
Data Processing Agreement (DPA)
Our standard DPA with SCCs — read the summary; signed copies on request.
Under NDA
Security whitepaper
How we architect, encrypt and monitor the platform end to end.
Under NDA
Subprocessor list
Every vendor that may process customer data — available publicly here.
Public

The numbers behind the trust.

24/7
Security Operations Center monitoring, staffed around the clock
99.9%
Platform uptime, tracked live on our status page
<72h
Breach-notification commitment to affected customers
AES-256
Encryption at rest, with TLS 1.3 in transit

How to get what you need.

Three steps, one business day. We keep it simple so your review isn't the thing that slows a deal down.

1

Email the trust team

Send a note to trust@crimsontalent.com with the documents you need and who's reviewing them. A customer contract or active evaluation helps us route you faster.

2

Sign a mutual NDA

We'll send a standard mutual NDA (or counter-sign yours). Most confidential materials — the SOC 2 report, pen-test summary and security whitepaper — are shared under this agreement.

3

Receive your documents

Once the NDA is in place we share the package securely, usually within one business day, and we're happy to walk your team through anything on a call.

Related resources.

The full detail behind our program lives across these pages.

Report a vulnerability: security researchers can reach our team at security@crimsontalent.com. See our responsible-disclosure policy.

Reviewing us as a vendor?

We've made vendor security reviews as painless as possible. Tell us what your team needs and we'll get the right documents in front of them — fast.

Request documents Read the security overview