Our commitment to you

Security & Trust
at every layer.

We take the protection of your data seriously. This page documents our security practices, compliance certifications, and privacy commitments.

Access Trust Center Documents

Sign up or sign in to view and download the latest versions of our SOC 2 reports, penetration test summaries, policies, and compliance documentation.

 

Compliance

Certifications & frameworks

We meet the most rigorous industry standards and undergo regular third-party audits to verify our controls.

SOC 2 Type II & SOC 3

Independently audited for security, availability, processing integrity, confidentiality, and privacy.

Certified
GDPR

Fully compliant with EU General Data Protection Regulation requirements including Data Processing Agreements.

Compliant
PCI DSS

Payment Card Industry Data Security Standard compliance for handling cardholder data within our infrastructure.

Compliant

Audit reports available under NDA. Request access →

Security

Security controls

A layered approach to protecting your data across infrastructure, access, and application layers.

Infrastructure

Encryption at rest & in transit

AES-256 at rest; TLS 1.2+ in transit. 

Cloud-native infrastructure

Hosted on NTT (Secure-24), Aptum, Liquid Web, and AWS across multiple availability zones with geo-redundant backups.

DDoS protection

Palo Alto Cloud Shield, F5 WAF, AWS Shield Advanced, and Cloudflare WAF protect against volumetric and application-layer attacks.

Penetration testing

Weekly network and application pennitration testing with remediations. Annual third-party pen tests by a CREST-accredited firm. Findings remediated within SLA.

Access & Operations

Least-privilege access

Role-based access controls enforced across all systems. Access reviewed and re-certified quarterly.

Multi-factor authentication

MFA mandatory for all employee accounts and available for customers via email or SMS tokens.

Security awareness training

All employees complete security and privacy training upon hire and annually, with phishing simulations.

Vulnerability management

Continuous scanning via CrowdStrike, ESET, and Qualys. Critical vulnerabilities patched when discovered.

Status

System uptime

Live and historical availability across our core services. Subscribe for real-time alerts.

100%
API — 90 days
100%
Web Services — 90 days
100%
Database — 90 days
100%
CDN — 90 days

Subscribe at status.cusg.com →

Privacy

Data privacy & retention

We are transparent about how we collect, process, and store your data — and how you can control it.

Data residency

Customer data is stored in multiple US data centers. Data never leaves our regions without consent.

Retention & deletion

You can delete your data at any time. Upon termination, all data is purged from production within 60 days and backups within 90 days.

Data subject rights

We honor all GDPR and CCPA requests — access, rectification, portability, erasure — within statutory timescales via our self-serve portal.

Data Processing Agreement

Our standard DPA is incorporated into our Terms of Service. Custom countersigned DPAs available for customers on request.

Subprocessors

Third-party subprocessors

Current list of sub-processors who may process customer data on our behalf. Last updated May, 2026.

Provider Purpose Service Region(s)
NTT (Secure-24) Private cloud infrastructure & storage Infrastructure US
Aptum Private cloud infrastructure & storage Infrastructure US, CA
Amazon Web Services Cloud infrastructure & storage Infrastructure US, CA
Cloudflare CDN, DDoS protection, DNS Networking Global
Stripe Payment processing Billing US, EU
Twilio Core MFA delivery SMS US
PostMark Transactional email delivery Email US
Salesforce Customer CRM, support, WIKI, and messaging Support US

We will notify you 30 days in advance of material changes.

FAQ

Frequently asked questions

We follow a documented Incident Response Plan aligned to NIST SP 800-61. In the event of a confirmed breach affecting customer data, we will notify affected customers within 72 hours in compliance with GDPR Article 33. Our security team operates a 24/7 on-call rotation to detect and respond to incidents.
Your data is stored in the NTT (Secure-24), Aptum, Liquid Web, or AWS regions we define. It is encrypted at rest with AES-256 and never leaves the region unless we notify clients of changes to replication for disaster recovery.
No. We do not use customer data to train, fine-tune, or evaluate any machine learning or AI models, nor do we share customer data with AI providers for training purposes.
We operate a responsible disclosure program. Report suspected vulnerabilities to [email protected]. We aim to acknowledge reports within 24 hours and resolve valid findings within our published SLA timescales. We do not pursue legal action against good-faith researchers.

Have a security question?

Our security team is available to answer questions or provide additional information.

For urgent incidents, include [URGENT] in your subject line.