Trust Center

Security and privacy you can verify.

At Incluud®, trust is the foundation of every partnership. Our security posture is built to earn and maintain that trust, protecting our systems and your data with industry-leading practices and a proactive, continuous-improvement mindset. This is a high-level overview of our program.

HIPAA
Aligned
SOC 2 Type 2
Audit in progress
NIST SP 800-53
Rev. 5 aligned
NIST AI RMF
AI governance
GDPR & CCPA
Data rights
EU AI Act
Aligned
Security & compliance foundation

Built on well-respected frameworks.

We designed our security program around established standards to ensure a comprehensive and defensible posture across our data, systems, and AI.

NIST SP 800-53 alignment

We leverage the NIST SP 800-53 Rev. 5 control catalog to guide our security policies and procedures, and run quarterly risk assessments aligned to the NIST Risk Management Framework.

SOC 2 Type 2

Currently finalizing our SOC 2 Type 2 audit.

NIST AI RMF

For our AI-driven systems, we use the NIST AI Risk Management Framework to govern development, emphasizing transparency, robustness, and accountability to mitigate bias and ensure model integrity.

Infrastructure & controls

A secure, compliant cloud foundation.

Our services are built and hosted on Microsoft Azure, whose certifications, including FedRAMP and ISO 27001, attest to the security of the underlying infrastructure. We layer our own controls on top.

Threat detection

Microsoft Defender for Cloud and Azure Sentinel actively monitor for and respond to security events across the environment.

Encryption everywhere

Data is encrypted in transit and at rest, with least-privilege access controls and strict authentication procedures.

Endpoint security

All company devices enforce hardening standards, automated patching, and EDR/XDR protection through centralized management.

Environment separation

Development, staging, and production are isolated, with audit logging across platform access for full oversight.

Policy & training

Our Information Security Policy mandates secure data handling and disposal, reinforced by monthly security-awareness training.

Continuous improvement

Quarterly NIST-aligned risk assessments plus third-party audits and penetration testing validate our controls over time.

Data governance & privacy

Privacy by design, governed and documented.

Our privacy and security practices are consolidated into a single, authoritative source of truth, defining governance, roles, and accountability, with ready-to-use playbooks and auditable evidence of program execution.

Principle

Privacy by design

Data protection is embedded throughout product development and business processes, not bolted on at the end.

Principle

Transparency & accountability

Clear ownership, documentation, and reporting for every privacy and security control we operate.

Playbooks

Ready when needed

Documented procedures for incident response, vendor management, data-subject requests, and regulatory reporting.

Coverage

Standards & regulations

Practices support compliance with applicable laws and contracts, including HIPAA security practices and GDPR/CCPA obligations.

Operations

Prepared for incidents, careful with vendors.

Incident response & notification

If a security incident occurs, we act quickly, follow applicable law, and prioritize clear communication, notifying account super-administrators in line with regulatory and contractual timelines:

  • GDPR: without undue delay, generally within 72 hours where applicable
  • State/provincial laws (e.g., CCPA): without unreasonable delay after containment and impact assessment
  • Documented Incident Response Playbook with a dedicated Security Operations team

Sub-processors & vendor risk

We vet every sub-processor through a rigorous process and monitor them on an ongoing basis:

  • Formal privacy and security review before engagement
  • Written contracts defining storage, processing, and security requirements
  • Ongoing monitoring to ensure standards are met
  • Account super-admins can subscribe to updates of our sub-processor list
Documentation

Need our security documentation?

We're happy to share a detailed overview of our security program under NDA, and to answer diligence questionnaires. Reach out and our team will follow up.

Security (CISO)[email protected]
Privacy (DPO)[email protected]
EU data protection[email protected]
Report an incident[email protected]