Encryption
TLS 1.3 in transit; AES-256 at rest. Customer-held key option via cloud-provider KMS for production tenants on enterprise tier.
Trust
This page reflects the current posture, not future promises. Status uses honest language: 'planned', 'mobilizing', 'in audit', 'Type I', 'Type II', 'continuous'. Reports and detailed artifacts are available under NDA before contracting.
Not started. On roadmap.
Auditor selected, kickoff scheduled.
Fieldwork active.
SOC 2 Type I report dated and available under NDA.
SOC 2 Type II observation window complete; report available under NDA.
Standing posture, not point-in-time.
Compliance posture
Data handling
These are platform behaviors, not aspirations. Specifics are expanded in the DPA and the security questionnaire pack.
TLS 1.3 in transit; AES-256 at rest. Customer-held key option via cloud-provider KMS for production tenants on enterprise tier.
Per-tenant logical isolation in the detection store. Cross-tenant retrieval is blocked at the query layer; the boundary is part of the eval set.
US (default), EU, and UK regions on the roadmap. Region selection is per-tenant at provisioning. Residency commitments are written into the order form, not a checkbox.
Detection telemetry retained per contracted window. Customer can shorten retention or trigger erasure within published SLAs. Evidence packs in incident cases follow case-retention policy, not telemetry retention.
SSO via OIDC / SAML, mandatory MFA for all IronSOC personnel. Just-in-time elevation with full audit. No standing production access.
Every analyst action, AI action, and policy change is logged immutably and exposed to the customer's tenant. The customer can replay any case end-to-end.
Sub-processors
The full sub-processor list with named vendors is delivered with the DPA. The categories below reflect what runs in production today and what is added before first paying customer.
Production compute, storage, and managed services
Hyperscaler in the customer's selected region. Provider name disclosed in the sub-processor list under DPA.
Internal application telemetry and platform logs
Vendor disclosed in the sub-processor list under DPA. Customer telemetry is not commingled into observability.
Workforce SSO and provisioning
Vendor disclosed in the sub-processor list under DPA.
Notifications and IR communications
Vendor disclosed in the sub-processor list under DPA.
Scanning IronSOC's own production surface
External attack surface and dependency scanning by independent provider.
Support ticketing and case management
Will be added in advance of first paying customer. Listed under DPA with notification rights.
Customer rights
Trust is contractual, not aesthetic. Every commitment below is available as document text — not as a marketing claim.
Standard DPA with EU Standard Contractual Clauses and the UK International Data Transfer Addendum. Available on request before contracting.
Customers receive the most recent SOC 2 / ISO 27001 reports under NDA. Direct audit available for enterprise tier under contract.
Material changes to the sub-processor list are notified at least 30 days in advance with right to object.
Notification within 72 hours of confirmed breach affecting customer data, in line with GDPR Article 33 and customer-specific contract obligations.
This page is updated within five business days of a status change. We keep a dated changelog visible to customers in their tenant. If a status here looks stale, it probably is — email us and we will either update it or explain the delay.