Security & Compliance

    AdvanceWork is built so protective-operations teams can trust their most sensitive data to the platform — protectee locations, schedules, and personnel records are protected by design, not bolted on after.

    Encryption in transit and at rest, row-level tenant isolation, SAML SSO, and US-only hosting on AWS form the baseline. Every control below is implemented and auditable today, with a SOC 2 Type 2 examination underway — so your security team can verify what we state rather than take our word for it.

    Compliance Posture, Stated Plainly

    We publish what we hold and what we do not. Nothing below is aspirational.

    SOC 2 Type 2

    Examination in progress

    All five Trust Services Criteria — Security, Availability, Confidentiality, Processing Integrity and Privacy. A wider scope than the Security-only report most vendors present. Report available under NDA on completion.

    GDPR

    Processor

    AdvanceWork is a processor for all customer data; your organisation is the controller. Article 28 processor terms are available in our Data Processing Agreement.

    CCPA / CPRA

    Service provider

    Service provider terms are included in the Data Processing Agreement. Customer personal data is never sold or shared for cross-context behavioural advertising.

    Penetration testing

    Annual, independent

    Independent penetration testing performed annually against the production perimeter. Summary available under NDA on request.

    How Customer Data Is Protected

    Four control areas, described as they are implemented today.

    Encryption

    Applied at the platform layer, not by convention.

    • TLS enforced on all application traffic and database connections
    • Encryption at rest for database, object storage and backups
    • Secrets held in KMS-encrypted parameter storage and 1Password
    • No secrets committed to source control

    Access Control

    Your identity policy governs access to the platform.

    • SAML 2.0 single sign-on configured per customer against your IdP
    • Role-based access, scoped by team and organisation
    • Production access limited to named administrators, MFA enforced
    • Break-glass account separate from daily accounts, use logged

    Secure Development

    Change control enforced by tooling rather than trust.

    • Pull request with independent approving review, enforced by ruleset
    • Automated security review posted into every pull request
    • Static analysis and Dependabot in the pipeline
    • Infrastructure defined in Terraform with drift detection

    Logging & Incident Response

    Audit trails held where operational roles cannot alter them.

    • Infrastructure audit logs in a segregated security account
    • In-application activity audit of user actions against records
    • Error monitoring with personal data scrubbed before transmission
    • Documented IR plan with named roles; no critical or high incidents to date

    Availability & Continuity

    Commitments we measure, with the risk we carry disclosed alongside them.

    Availability commitment

    99.5% monthly

    Recovery window

    Rolling 7-day point-in-time recovery

    Recovery objectives

    RPO 1 hour · RTO 8 hours

    Restoration testing

    Scheduled, with integrity verification documented

    Continuity plan

    Documented BCDR plan, available under NDA

    Status page

    90-day uptime history and incident records

    Artificial Intelligence — Bring Your Own

    There is no AI provider in AdvanceWork's processing chain. We do not operate a managed AI account that processes customer data, and no AI provider appears on our subprocessor list.

    • Connect your own provider to your own tenant through the Model Context Protocol
    • Your AI credentials remain yours — AdvanceWork never holds them
    • Not enabled by default, and can be disabled at tenant level
    • The provider is engaged under your agreement, so AI governance stays with you
    Read how bring-your-own AI works

    Documents Available

    All security documents are confidential and shared under NDA — ask and we will send the current version.

    Trust Center

    Under NDA

    Live control status, security documents and the current subprocessor list.

    Privacy notice

    Under NDA

    How AdvanceWork handles personal data as a controller and as a processor.

    Security overview

    Under NDA

    Architecture, data flows, controls and shared responsibilities in one document.

    Security questionnaire responses

    Under NDA

    85 pre-answered questions across governance, hosting, identity, development and exit.

    Data Processing Agreement

    Under NDA

    Article 28 terms, Annex I data categories, Annex II measures, Annex III subprocessors.

    SOC 2 Type 2 report

    Under NDA

    Released under NDA on completion of the examination.

    Penetration test summary

    Under NDA

    Summary of the most recent independent penetration test.

    IR and BCDR plans

    Under NDA

    Incident response plan, business continuity plan and access review results.

    Security Questions?

    Have a security question or need a specific control verified? We're glad to walk your team through it.

    Privacy and data protection: [email protected]

    AdvanceWork LLC · 7700 Windrose Ave, Suite G-300, Plano, TX 75024