Skip to main content
Argitron
Menu

Trust center

The page your procurement team is asking for.

Compliance attestations

Pursuing SOC 2 Type II (target H2 2026) and ISO 27001 (target 2027). Status updated quarterly. We won't claim what we haven't earned.

Data residency

Self-hosted only — your data never leaves your infrastructure. We do not run a cloud-managed offering year 1.

Sub-processors

Versioned list, downloadable. Email-on-change subscription available. Updated for any vendor that touches customer-attributable data.

DPA

Standard DPA available for download (PDF, signed). Custom MSAs at Enterprise tier.

Encryption posture

TLS 1.3 in transit. AES-256-GCM at rest. Optional customer-managed keys (KMS / Vault / HSM). HSTS preloaded.

Access controls

Least privilege, just-in-time, audit-logged. Quarterly access recertification. SSO mandatory for staff, MFA mandatory everywhere.

Penetration testing

Annual minimum, quarterly aspirational. Executive summary on request, full report under NDA.

Sub-processor change notification

30-day advance notice via the email subscription. Customers can object before the change takes effect.

Status page

Public status page at status.argitron.com (coming soon). Built from our own /status.json endpoint — eat our own dogfood.