Trust centre

The reports, the subprocessors and the practices, on one page. Ask for any document and we send it the same day.

SOC 2 Type II · ISO 27001 · 1,400 security teams

Risk score4 open
/100
Risk score 82. 4 open
  • Stale admin accountLeft the company 212 days ago and is still a global adminHigh
  • Leaked API keyFound in a public repository six hours agoCritical
  • Contractor · MFA offSigns in to production with a password onlyHigh
  • Laptop · 41 days unpatchedThree critical fixes are waiting to installMedium

Trust centre

The reports, the subprocessors and the practices, on one page. Ask for any document and we send it the same day.

SOC 2 Type II · ISO 27001 · 1,400 security teams

Risk score4 open
/100
Risk score 82. 4 open
  • Stale admin accountLeft the company 212 days ago and is still a global adminHigh
  • Leaked API keyFound in a public repository six hours agoCritical
  • Contractor · MFA offSigns in to production with a password onlyHigh
  • Laptop · 41 days unpatchedThree critical fixes are waiting to installMedium

Trust centre

The reports, the subprocessors and the practices, on one page. Ask for any document and we send it the same day.

SOC 2 Type II · ISO 27001 · 1,400 security teams

Risk score3 open
/100
Risk score 82. 3 open
  • Stale admin accountLeft the company 212 days ago and is still a global adminHigh
  • Leaked API keyFound in a public repository six hours agoCritical
  • Contractor · MFA offSigns in to production with a password onlyHigh

Reports

We ask customers for evidence, so we publish ours. Every report below is available to customers and to prospects under NDA.

0 / 6 reports current

  • Current

    SOC 2 Type II

    Audited every year by an independent firm. Covers security, availability and confidentiality.

    Request
  • Certified

    ISO 27001

    The certificate covers the platform, the company and the people who run it.

    Request
  • In effect

    GDPR

    Data processing agreement and standard contractual clauses, ready to sign.

    Request
  • In effect

    HIPAA

    Business associate agreement on the Business and Enterprise plans.

    Request
  • Twice a year

    Penetration test

    Independent testers attack the platform. The summary letter is yours on request.

    Request
  • In progress

    ISO 27701

    Privacy extension to our ISO 27001 scope. The audit is booked.

    Request

Sample reports, vendors and regions — demo data. Replace them with your own before you publish.

  1. Read-only by default

    Every source connects with a read-only role. A fix that changes something uses a separate permission you grant per action.

  2. Findings, never content

    We store what is exposed and where. We do not store the content of your files, mail or messages.

  3. Encrypted everywhere

    TLS 1.3 in transit and AES-256 at rest, with keys held in a managed key service and rotated on a schedule.

  4. Access by named people

    Staff access to production needs SSO, a hardware key and a ticket. Every session is logged and reviewed.

  5. Tested before it ships

    Every change is reviewed by a second engineer and scanned for secrets and known flaws before it is merged.

  6. A plan for the bad day

    Incidents follow a written plan. If your data is affected you hear from us within 72 hours, with what we know.

You pick the region at sign-up and it does not change unless you ask. Enterprise plans can run in a private region.

  • European UnionFrankfurt and DublinData never leaves the EU
  • United KingdomLondonFor UK public sector and finance
  • United StatesVirginia and OregonThe default for US accounts

The vendors that process customer data on our behalf. We tell customers 30 days before a new one is added.

Subprocessors
VendorPurposeRegion
Amazon Web ServicesHosting, storage and key managementEU, UK, US
CloudflareNetwork edge and protection from floods of trafficGlobal
PostmarkSending alert and account emailsUS
StripeCard payments and invoicesUS, EU
SentryError reports from the app, without customer dataEU

Last updated 1 October 2026

Need the full report?

Tell us which document you need and who should receive it. Reports are shared under NDA, usually the same working day.

Reports

We ask customers for evidence, so we publish ours. Every report below is available to customers and to prospects under NDA.

0 / 6 reports current

  • Current

    SOC 2 Type II

    Audited every year by an independent firm. Covers security, availability and confidentiality.

    Request
  • Certified

    ISO 27001

    The certificate covers the platform, the company and the people who run it.

    Request
  • In effect

    GDPR

    Data processing agreement and standard contractual clauses, ready to sign.

    Request
  • In effect

    HIPAA

    Business associate agreement on the Business and Enterprise plans.

    Request
  • Twice a year

    Penetration test

    Independent testers attack the platform. The summary letter is yours on request.

    Request
  • In progress

    ISO 27701

    Privacy extension to our ISO 27001 scope. The audit is booked.

    Request

Sample reports, vendors and regions — demo data. Replace them with your own before you publish.

  1. Read-only by default

    Every source connects with a read-only role. A fix that changes something uses a separate permission you grant per action.

  2. Findings, never content

    We store what is exposed and where. We do not store the content of your files, mail or messages.

  3. Encrypted everywhere

    TLS 1.3 in transit and AES-256 at rest, with keys held in a managed key service and rotated on a schedule.

  4. Access by named people

    Staff access to production needs SSO, a hardware key and a ticket. Every session is logged and reviewed.

  5. Tested before it ships

    Every change is reviewed by a second engineer and scanned for secrets and known flaws before it is merged.

  6. A plan for the bad day

    Incidents follow a written plan. If your data is affected you hear from us within 72 hours, with what we know.

You pick the region at sign-up and it does not change unless you ask. Enterprise plans can run in a private region.

  • European UnionFrankfurt and DublinData never leaves the EU
  • United KingdomLondonFor UK public sector and finance
  • United StatesVirginia and OregonThe default for US accounts

The vendors that process customer data on our behalf. We tell customers 30 days before a new one is added.

Subprocessors
VendorPurposeRegion
Amazon Web ServicesHosting, storage and key managementEU, UK, US
CloudflareNetwork edge and protection from floods of trafficGlobal
PostmarkSending alert and account emailsUS
StripeCard payments and invoicesUS, EU
SentryError reports from the app, without customer dataEU

Last updated 1 October 2026

Need the full report?

Tell us which document you need and who should receive it. Reports are shared under NDA, usually the same working day.

Reports

We ask customers for evidence, so we publish ours. Every report below is available to customers and to prospects under NDA.

0 / 6 reports current

  • Current

    SOC 2 Type II

    Audited every year by an independent firm. Covers security, availability and confidentiality.

    Request
  • Certified

    ISO 27001

    The certificate covers the platform, the company and the people who run it.

    Request
  • In effect

    GDPR

    Data processing agreement and standard contractual clauses, ready to sign.

    Request
  • In effect

    HIPAA

    Business associate agreement on the Business and Enterprise plans.

    Request
  • Twice a year

    Penetration test

    Independent testers attack the platform. The summary letter is yours on request.

    Request
  • In progress

    ISO 27701

    Privacy extension to our ISO 27001 scope. The audit is booked.

    Request

Sample reports, vendors and regions — demo data. Replace them with your own before you publish.

  1. Read-only by default

    Every source connects with a read-only role. A fix that changes something uses a separate permission you grant per action.

  2. Findings, never content

    We store what is exposed and where. We do not store the content of your files, mail or messages.

  3. Encrypted everywhere

    TLS 1.3 in transit and AES-256 at rest, with keys held in a managed key service and rotated on a schedule.

  4. Access by named people

    Staff access to production needs SSO, a hardware key and a ticket. Every session is logged and reviewed.

  5. Tested before it ships

    Every change is reviewed by a second engineer and scanned for secrets and known flaws before it is merged.

  6. A plan for the bad day

    Incidents follow a written plan. If your data is affected you hear from us within 72 hours, with what we know.

You pick the region at sign-up and it does not change unless you ask. Enterprise plans can run in a private region.

  • European UnionFrankfurt and DublinData never leaves the EU
  • United KingdomLondonFor UK public sector and finance
  • United StatesVirginia and OregonThe default for US accounts

The vendors that process customer data on our behalf. We tell customers 30 days before a new one is added.

Subprocessors
VendorPurposeRegion
Amazon Web ServicesHosting, storage and key managementEU, UK, US
CloudflareNetwork edge and protection from floods of trafficGlobal
PostmarkSending alert and account emailsUS
StripeCard payments and invoicesUS, EU
SentryError reports from the app, without customer dataEU

Last updated 1 October 2026

Need the full report?

Tell us which document you need and who should receive it. Reports are shared under NDA, usually the same working day.

Questions

What security and IT teams want to know before they connect the first source.

Answered.

Connect your identity provider and most teams see their first findings in under an hour. Cloud accounts and device managers each add a few minutes. Nothing is installed on a server to get started.

Questions

What security and IT teams want to know before they connect the first source.

Answered.

Connect your identity provider and most teams see their first findings in under an hour. Cloud accounts and device managers each add a few minutes. Nothing is installed on a server to get started.

Questions

What security and IT teams want to know before they connect the first source.

Answered.

Connect your identity provider and most teams see their first findings in under an hour. Cloud accounts and device managers each add a few minutes. Nothing is installed on a server to get started.

Start here

Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.

Nothing is scanned until you connect a source. No card needed.

We will sweep

  • Identity providerNot connected
  • Cloud accountsNot connected
  • DevicesNot connected
  • Code repositoriesNot connected

Start here

Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.

Nothing is scanned until you connect a source. No card needed.

We will sweep

  • Identity providerNot connected
  • Cloud accountsNot connected
  • DevicesNot connected
  • Code repositoriesNot connected

Start here

Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.

Nothing is scanned until you connect a source. No card needed.

We will sweep

  • Identity providerNot connected
  • Cloud accountsNot connected
  • DevicesNot connected
  • Code repositoriesNot connected
Palisade

Palisade watches every identity, device and key your company runs on, finds what is exposed and closes it before it turns into a breach.

Book a demo
© 2026 Palisade Security Ltd. All rights reserved. All systems securedPrivacyTermsCookies
Palisade

Palisade watches every identity, device and key your company runs on, finds what is exposed and closes it before it turns into a breach.

Book a demo
© 2026 Palisade Security Ltd. All rights reserved. All systems securedPrivacyTermsCookies
Palisade

Palisade watches every identity, device and key your company runs on, finds what is exposed and closes it before it turns into a breach.

Book a demo
© 2026 Palisade Security Ltd. All rights reserved. All systems securedPrivacyTermsCookies

Create a free website with Framer, the website builder loved by startups, designers and agencies.