Trust and data handling

Security & Data Handling

Your control library contains your institution's internal obligation mapping. Regloom treats that data as sensitive by design: encryption in transit and at rest, access controls that follow the principle of least privilege, and an audit trail you can pull at any time. Below is what we have built and what we have not yet built.

Data in Transit

All data transmitted between your browser or integrations and Regloom servers is encrypted using TLS 1.3. Connections using older TLS versions (1.0, 1.1) are rejected. API access uses HTTPS with certificate pinning available on the Institution plan. Internal service-to-service traffic within the Regloom infrastructure is also encrypted in transit.

TLS 1.3 HTTPS enforced HSTS enabled

Data at Rest

Control library data, mapping records, and audit trail entries are encrypted at rest using AES-256. Database encryption is managed at the storage layer. Encryption keys are rotated annually and managed through a hardware security module (HSM). Backup data is encrypted with the same key hierarchy as live data.

AES-256 HSM key management Encrypted backups

Access Control

Regloom supports SSO via SAML 2.0 on the Institution plan and OAuth 2.0 for Professional plan accounts. Within the application, role-based access control (RBAC) allows administrators to define which users can view, approve, or override control mappings. All access events are logged. Regloom staff do not have standing access to customer control library data; access for support purposes requires explicit customer authorization and is time-limited.

SAML 2.0 SSO RBAC Least-privilege staff access

Data Residency

All Regloom data, including control library content, mapping records, and audit trails, is stored and processed in the United States. We use AWS infrastructure in US regions. Data is not transferred to infrastructure outside the United States. EU or multi-region data residency is not currently available; contact us if this is a requirement for your institution.

US data residency AWS US regions

Retention Policy

Control library data and mapping records are retained for the duration of your subscription plus 90 days after termination to allow export. Audit trail records are retained for a minimum of 7 years to support long-term exam preparation. Regulatory source content cached for processing is purged after 30 days. You can request deletion of your data at any time; control library data will be deleted within 14 days of a verified deletion request.

Penetration Testing

Regloom engages an independent security firm for annual penetration testing of the application layer and API. Testing covers authentication, authorization, injection vectors, and data exposure risks. Findings are remediated within a defined SLA based on severity (critical: 24 hours, high: 7 days, medium: 30 days). Penetration test summaries are available to Institution plan customers under NDA upon request.

Annual third-party pentest Summary available on request

Incident Response

If a security incident affects customer data, Regloom will notify affected customers within 72 hours of confirmed breach detection, consistent with applicable law. Notification will include the nature of the incident, data categories affected, and the remediation steps underway. We maintain an incident response plan reviewed annually and tested with tabletop exercises.

On SOC 2: Regloom has been built with SOC 2 Type II controls in mind, including access control logging, change management process, and availability monitoring. We have not yet completed a formal SOC 2 Type II audit. If a current SOC 2 report is a vendor requirement for your institution, reach out and we will discuss our security documentation package and expected audit timeline.

72-hour breach notification Built with SOC 2 controls in mind

Security questions? Contact us at [email protected]. For security disclosures, please use the same address with subject "Security Disclosure."