Skip to content

Trust Center

Enterprise-grade security, compliance, and transparency. Download our complete security package and compliance documentation.

Certifications & Compliance

Independently audited and verified

Certified

SOC 2 Type II

Annual audit by independent CPA firm. Covers Security, Availability, and Confidentiality Trust Service Criteria.

Last Audit: Q3 2024

Download Report
Certified

ISO 27001:2022

Information Security Management System (ISMS) certified. Demonstrates systematic approach to managing sensitive information.

Last Audit: Q2 2024

Download Report
Compliant

WCAG 2.2 AA

Web Content Accessibility Guidelines Level AA conformance. Independently tested and verified.

Last Audit: Q4 2024

Download Report

Security Practices

How we protect your data

Data Encryption

AES-256 encryption at rest, TLS 1.3 in transit. All data encrypted with customer-specific keys managed via AWS KMS.

Data Residency

All customer data stored in US-based AWS regions (us-east-1, us-west-2). No international data transfers without explicit consent.

Security Monitoring

24/7 SOC monitoring, intrusion detection, vulnerability scanning. Annual penetration testing by third-party security firm.

Audit Logging

Immutable audit logs for all system access and data changes. Retained for 7 years to support forensic investigation.

SLA Guarantees

Our commitment to reliability

99.95%
Platform Uptime

Monthly SLA guarantee with financial credits for downtime

< 4 hours
Incident Response

Time to acknowledge P1 incidents (business-critical)

< 1 hour
Security Response

Time to initial response for security incidents

99.9%
API Availability

REST API uptime guarantee with real-time status dashboard

Accessibility Conformance

WCAG 2.2 Level AA Compliance

VPAT® and Accessibility Conformance Report (ACR)

Our platform has been independently tested for conformance with Web Content Accessibility Guidelines (WCAG) 2.2 Level AA and Section 508 standards.

WCAG 2.2 Level AA

Full conformance across all success criteria

Section 508

Compliant with revised Section 508 standards

EN 301 549

European accessibility standard compliance

Last updated: December 2024 | Testing performed by: [THIRD_PARTY_AUDITOR_PLACEHOLDER]

Complete Security Package

Download our comprehensive security and compliance documentation for procurement and due diligence.

Package Contents

  • SOC 2 Type II Report (with management response)
  • ISO 27001:2022 Certificate
  • VPAT® 2.5 and Accessibility Conformance Report
  • Security Architecture Diagrams
  • Data Processing Agreement (DPA) template
  • Business Associate Agreement (BAA) template
  • Incident Response Plan summary
  • Disaster Recovery & Business Continuity Plans
  • Penetration Test Executive Summary
  • Vendor Security Questionnaire (pre-filled)
Download Complete Package (24 MB)

Password-protected archive. Contact security@nxgnt.com for access credentials.

Security Questions?

Our security team is available to answer procurement questions, schedule security reviews, or discuss custom compliance requirements.