Access Trust Center Documents
Sign up or sign in to view and download the latest versions of our SOC 2 reports, penetration test summaries, policies, and compliance documentation.
Compliance
Certifications & frameworks
We meet the most rigorous industry standards and undergo regular third-party audits to verify our controls.
SOC 2 Type II & SOC 3
Independently audited for security, availability, processing integrity, confidentiality, and privacy.
CertifiedGDPR
Fully compliant with EU General Data Protection Regulation requirements including Data Processing Agreements.
CompliantPCI DSS
Payment Card Industry Data Security Standard compliance for handling cardholder data within our infrastructure.
CompliantAudit reports available under NDA. Request access →
Security
Security controls
A layered approach to protecting your data across infrastructure, access, and application layers.
Infrastructure
Encryption at rest & in transit
AES-256 at rest; TLS 1.2+ in transit.
Cloud-native infrastructure
Hosted on NTT (Secure-24), Aptum, Liquid Web, and AWS across multiple availability zones with geo-redundant backups.
DDoS protection
Palo Alto Cloud Shield, F5 WAF, AWS Shield Advanced, and Cloudflare WAF protect against volumetric and application-layer attacks.
Penetration testing
Weekly network and application pennitration testing with remediations. Annual third-party pen tests by a CREST-accredited firm. Findings remediated within SLA.
Access & Operations
Least-privilege access
Role-based access controls enforced across all systems. Access reviewed and re-certified quarterly.
Multi-factor authentication
MFA mandatory for all employee accounts and available for customers via email or SMS tokens.
Security awareness training
All employees complete security and privacy training upon hire and annually, with phishing simulations.
Vulnerability management
Continuous scanning via CrowdStrike, ESET, and Qualys. Critical vulnerabilities patched when discovered.
Status
System uptime
Live and historical availability across our core services. Subscribe for real-time alerts.
Subscribe at status.cusg.com →
Privacy
Data privacy & retention
We are transparent about how we collect, process, and store your data — and how you can control it.
Data residency
Customer data is stored in multiple US data centers. Data never leaves our regions without consent.
Retention & deletion
You can delete your data at any time. Upon termination, all data is purged from production within 60 days and backups within 90 days.
Data subject rights
We honor all GDPR and CCPA requests — access, rectification, portability, erasure — within statutory timescales via our self-serve portal.
Data Processing Agreement
Our standard DPA is incorporated into our Terms of Service. Custom countersigned DPAs available for customers on request.
Subprocessors
Third-party subprocessors
Current list of sub-processors who may process customer data on our behalf. Last updated May, 2026.
| Provider | Purpose | Service | Region(s) |
|---|---|---|---|
| NTT (Secure-24) | Private cloud infrastructure & storage | Infrastructure | US |
| Aptum | Private cloud infrastructure & storage | Infrastructure | US, CA |
| Amazon Web Services | Cloud infrastructure & storage | Infrastructure | US, CA |
| Cloudflare | CDN, DDoS protection, DNS | Networking | Global |
| Stripe | Payment processing | Billing | US, EU |
| Twilio | Core MFA delivery | SMS | US |
| PostMark | Transactional email delivery | US | |
| Salesforce | Customer CRM, support, WIKI, and messaging | Support | US |
We will notify you 30 days in advance of material changes.
FAQ
Frequently asked questions
Have a security question?
Our security team is available to answer questions or provide additional information.
For urgent incidents, include [URGENT] in your subject line.