Twenty-one commitments — written down.
Every Enterprise contract ships with the controls below. Procurement, security, and legal can pre-review against your standard checklist before the first call.
- SOC2 Type II reportType II audit kickoff Q2 2026. Report available under NDA once issued. Trust services criteria: Security, Availability, Confidentiality.
- BAA for HIPAAExecutable Business Associate Agreement for covered entities and business associates.
- GDPR data residencyEU-only data plane available — customer data, backups, and derived telemetry stay in-region.
- Sub-processor list with DPAsNamed processors, executed Data Processing Agreements, and categories of data documented on the trust center.
- 99.95% contractual SLAService credits stack to 100% of monthly fee for breaches below 99.0%. Higher tiers available.
- Status page with 90-day historyPublic uptime, incident timeline, and post-mortem index.
- Defined incident responseSEV-1 acknowledged within 15 minutes; named on-call escalation; written RCA within 5 business days.
- Dedicated tenant regionChoose US, EU, or APAC. Data, compute, and cache stay in-region — sub-processors included.
- Per-customer encryption keysCustomer-managed encryption keys (CMEK) and bring-your-own-key (BYOK) supported on dedicated tenants.
- Network isolationPrivate-link ingress and egress, customer VPC peering, IP allowlists on the admin plane.
- SSO — SAML and OIDCOkta, Azure AD, Ping Identity, Google Workspace, JumpCloud, OneLogin out of the box.
- SCIM 2.0 provisioningJust-in-time user provisioning, automated deprovisioning on offboarding, group-to-role sync.
- Custom JWT claimsInject identity-provider claims into end-user app sessions for downstream authorization.
- 24/7 priority supportShared Slack or Teams channel, 15-minute SEV-1 response, dedicated escalation rotation.
- Named Customer Success ManagerSingle point of contact for roadmap influence, quarterly business reviews, and feature requests.
- White-glove migrationWritten cutover runbook, parallel-run support, documented rollback plan from your incumbent stack.
- Quarterly business reviewUsage trend report, security posture update, roadmap preview, and renewal planning.
- Custom MSA + DPAMaster Services Agreement and Data Processing Agreement negotiable through your legal team.
- Net-60 ACH / wireInvoice billing on annual prepay terms. PO-referenced, W-9 and W-8BEN-E on file.
- Annual contractsSingle-year and multi-year terms with reserved-capacity discounts.
- Vendor onboarding portalsCoupa, SAP Ariba, Jaggaer supported — your AP team will not get stuck.
Everything your security team needs.
- SOC2 Type II status — current report + scope statement.
- Sub-processor list — named providers, executed DPAs, region of processing.
- Security questionnaire — pre-filled CAIQ + SIG-Lite, returned in 48 business hours.
- BAA / DPA / MSA templates — redline start points for your legal team.
- Pentest summary letter — latest third-party penetration test cover sheet.
Anonymized under NDA. Named references available on request during evaluation.
Talk to us.
One round of triage; one named contact within one business day; one scoped POC plan within five.
What procurement always asks.
Audit kickoff Q2 2026 — we are in the observation window now. Report will be available under NDA once issued. Until then, we can share our current SOC2 readiness assessment and design-stage controls documentation under NDA — request via the intake form above. Trust services criteria: Security, Availability, Confidentiality.
Yes, on dedicated tenant deployments. We support customer VPC peering, private-link ingress, and IP allowlists on the admin plane.
30 days from termination. Certified destruction reports issued on request, with crypto-shredding evidence for encrypted backups.
Yes. The EU region runs an EU-only data plane — customer data, derived telemetry, and backups stay in-region. Sub-processors are documented per region.
Enterprise pricing is custom-fit to your scale, residency, and contract term. Most engagements start in the high-five-figures annually, with reserved-capacity and multi-year discounts available.
Yes — a 30-day paid POC with a proof-of-architecture deliverable, scoped against your incumbent migration. Credits convert toward annual contract on close.
No customer data is used to train any LLM. The agent surface (MCP) is provisioning-only, sandboxed per project, and audit-logged. Prompt-injection controls are documented in the trust center.
One contract. One backend. Six fewer vendors.
Tell us the stack you're consolidating, the compliance posture you need, and your target go-live. We'll come back with a scoped POC plan.