Trust & compliance
Security posture, spelled out.
The compliance posture Nightglass ships under, in the same shape the FAQ opens with but with the answers behind every badge — independent audits, data residency, sub-processor transparency, and the BAA / single-tenant controls the Enterprise tier unlocks.
SOC 2 Type II
ISO 27001
HIPAA · BAA
EU residency
What the badges mean in practice
Four pillars, audited.
Every badge above earns its place on a single grid below — the audit, the residency, the sub-processor list, and the BAA plus single-tenant controls the Enterprise tier unlocks.
Independent audits
SOC 2 Type II and ISO 27001 reports are available under NDA. The same controls that survived the audit gate the auto-PR path the desk uses to open fixes — the on-call review on top of the same evidence pack we hand to auditors, in the same shape.
Data residency
EU customers pin signals and postmortems to our Frankfurt region; US customers pin to Virginia. Region selection is a tenant setting, not a sales-engineering project — flip it on day one and the desk routes the same way the rest of your stack already does.
Sub-processor transparency
The sub-processor list and a current evidence pack are both available on request. Every integration the desk talks to — alert sources, Git hosts, chat platforms — is named, scoped, and on a page your security team can audit without a sales call in the loop.
BAA & enterprise controls
HIPAA coverage sits on the Enterprise tier today, behind a signed Business Associate Agreement. Single-tenant deploy behind your VPC is part of the same tier — your data, your perimeter, the desk running on your infrastructure rather than ours.
Bring Nightglass into the rotation
The desk ships with the evidence pack.
Pick a plan and request the SOC 2 / ISO 27001 evidence pack under NDA, or book a working session with the team that builds it.
next step
Request the evidence pack.
NDA-ready reports delivered to your security team on request.
See pricingRequest a demo