Enterprise-Grade Security & Compliance
Your supply chain data is protected by industry-leading security practices and infrastructure.
Infrastructure Security
- Hosted on SOC 2 Type II certified infrastructure
- Encryption at rest (AES-256)
- Encryption in transit (TLS 1.3)
- Regular penetration testing
- 24/7 security monitoring
Access Controls
- Role-based access control (RBAC)
- Multi-factor authentication (MFA)
- Single Sign-On (SSO) available
- Session management
- Comprehensive audit logging
Compliance Support
- SOC 2 Type II infrastructure
- GDPR compliant
- CMMC-aligned architecture
- Supports NIST 800-171 controls
- Regular security audits
Data Governance
- You own your data
- Data export anytime
- Vendor data isolation
- Retention controls
- Secure deletion
Certifications & Attestations
Our security posture is validated by industry-recognized certifications.
SOC 2 Type II
Infrastructure
GDPR Compliant
Data Privacy
CMMC-Aligned
Architecture
GSA Schedule
Available
How We Protect Your Data
Multiple layers of security protect your supply chain intelligence at every stage.
1
Data in Transit
- TLS 1.3 encryption
- Certificate pinning
- Secure API endpoints
2
Data at Rest
- AES-256 encryption
- Encrypted backups
- Key management service
3
Access Control
- MFA enforcement
- IP allowlisting (Enterprise)
- Session timeout
4
Monitoring
- 24/7 threat detection
- Intrusion prevention
- Anomaly detection
5
Incident Response
- 24-hour response time
- Customer notification
- Remediation process
Responsible Disclosure
We take security seriously. If you discover a vulnerability, please report it to security@measuredrisk.com.
We commit to:
- Acknowledge within 24 hours
- Investigate and remediate promptly
- Keep you informed of progress
- Recognize responsible researchers
Please do not exploit vulnerabilities or access customer data during your research.
Security FAQs
Where is data hosted?
United States (AWS/GCP SOC 2 certified data centers). Enterprise customers may request specific region deployments.
Who has access to my data?
Only your authorized users. MeasuredRisk staff cannot access your vendor data without explicit permission for support purposes.
How often are backups taken?
Daily automated backups, retained for 90 days. Enterprise customers can request custom backup schedules.
Do you share data with third parties?
No. We never share your vendor data. See our Privacy Policy for details on limited service provider usage.
Is MeasuredRisk FedRAMP certified?
We're building toward FedRAMP authorization. Currently available via GSA Schedule with architecture aligned to CMMC requirements.
Can I run a security assessment?
Yes. Enterprise customers can request security questionnaires, SOC 2 reports, and penetration test results.
Questions About Security?
Our security team is here to help. Reach out for security documentation, questionnaires, or to discuss your requirements.