ITOrigin Logo
Security Center

Trust &Security

Security is at the core of everything we do. Learn about our comprehensive security practices, certifications, and commitment to protecting your data.

All Systems Operational

Last updated: 7/18/2026, 1:09:31 PM

View Status Page →

Certifications & Compliance

Third-party validated security controls and regulatory compliance.

Certified

ISO 27001:2022

Information Security Management System

Valid through December 2026

Certified

SOC 2 Type II

Service Organization Control

Audit completed October 2024

Compliant

GDPR

General Data Protection Regulation

Continuously maintained

Compliant

HIPAA

Health Insurance Portability and Accountability Act

BAA available upon request

Compliant

PCI-DSS

Payment Card Industry Data Security Standard

Level 1 Service Provider

Registered

CSA STAR

Cloud Security Alliance STAR Registry

Level 1 Self-Assessment

Security Practices

How we protect your data and maintain the security of our platform.

Encryption

  • AES-256 encryption for data at rest
  • TLS 1.3 for all data in transit
  • Hardware Security Modules for key management
  • Customer-managed encryption keys (BYOK) available

Access Control

  • Role-based access control (RBAC)
  • Multi-factor authentication enforced
  • Single Sign-On (SSO) with SAML/OIDC
  • Least privilege access principles

Infrastructure Security

  • SOC 2 certified cloud providers
  • Network segmentation and isolation
  • Regular vulnerability scanning
  • Automated patch management

Data Protection

  • Geographic data residency options
  • Automated daily backups
  • Point-in-time recovery
  • Data retention controls

Responsible Disclosure

We appreciate the security research community's efforts in helping us maintain the security of our platform. If you discover a vulnerability, please report it responsibly.

Report a Vulnerability

  • • Email: security@itorigin.com
  • • PGP Key: Available upon request
  • • Response time: Within 48 hours

We commit to working with researchers to understand and resolve issues quickly, and we will not pursue legal action against good-faith security research.

Have Security Questions?

Our security team is available to answer questions about our security practices, provide compliance documentation, or discuss your specific requirements.