Enterprise-Grade Security & Compliance

Your supply chain data is protected by industry-leading security practices and infrastructure.

Infrastructure Security

  • Hosted on SOC 2 Type II certified infrastructure
  • Encryption at rest (AES-256)
  • Encryption in transit (TLS 1.3)
  • Regular penetration testing
  • 24/7 security monitoring

Access Controls

  • Role-based access control (RBAC)
  • Multi-factor authentication (MFA)
  • Single Sign-On (SSO) available
  • Session management
  • Comprehensive audit logging

Compliance Support

  • SOC 2 Type II infrastructure
  • GDPR compliant
  • CMMC-aligned architecture
  • Supports NIST 800-171 controls
  • Regular security audits

Data Governance

  • You own your data
  • Data export anytime
  • Vendor data isolation
  • Retention controls
  • Secure deletion

Certifications & Attestations

Our security posture is validated by industry-recognized certifications.

SOC 2 Type II

Infrastructure

GDPR Compliant

Data Privacy

CMMC-Aligned

Architecture

GSA Schedule

Available

How We Protect Your Data

Multiple layers of security protect your supply chain intelligence at every stage.

1

Data in Transit

  • TLS 1.3 encryption
  • Certificate pinning
  • Secure API endpoints

2

Data at Rest

  • AES-256 encryption
  • Encrypted backups
  • Key management service

3

Access Control

  • MFA enforcement
  • IP allowlisting (Enterprise)
  • Session timeout

4

Monitoring

  • 24/7 threat detection
  • Intrusion prevention
  • Anomaly detection

5

Incident Response

  • 24-hour response time
  • Customer notification
  • Remediation process

Responsible Disclosure

We take security seriously. If you discover a vulnerability, please report it to security@measuredrisk.com.

We commit to:

  • Acknowledge within 24 hours
  • Investigate and remediate promptly
  • Keep you informed of progress
  • Recognize responsible researchers

Please do not exploit vulnerabilities or access customer data during your research.

Security FAQs

Where is data hosted?

United States (AWS/GCP SOC 2 certified data centers). Enterprise customers may request specific region deployments.

Who has access to my data?

Only your authorized users. MeasuredRisk staff cannot access your vendor data without explicit permission for support purposes.

How often are backups taken?

Daily automated backups, retained for 90 days. Enterprise customers can request custom backup schedules.

Do you share data with third parties?

No. We never share your vendor data. See our Privacy Policy for details on limited service provider usage.

Is MeasuredRisk FedRAMP certified?

We're building toward FedRAMP authorization. Currently available via GSA Schedule with architecture aligned to CMMC requirements.

Can I run a security assessment?

Yes. Enterprise customers can request security questionnaires, SOC 2 reports, and penetration test results.

Questions About Security?

Our security team is here to help. Reach out for security documentation, questionnaires, or to discuss your requirements.

Contact Security Team Request Security Documentation