Security

How we protect your data, and what we commit to contractually

Our security commitments

Every commitment on this page is written into our Terms of Service, not just described in marketing copy. Current customers can request our latest reports directly.

Your data is never used to train AI models

OpenGRC includes AI features that process your data at your direction. We do not use Customer Data to train, fine-tune, or otherwise improve artificial intelligence or machine learning models, and we do not permit our subprocessors to do so. Outputs generated from your data are your data.

This is a contractual commitment (Terms of Service §4.11), not a policy we can quietly revise.

Independent audit and testing

  • SOC 2 Type II. We maintain a SOC 2 Type II examination of the service, performed at least annually by an independent auditor. Our most recent report is available to customers on request, under NDA.
  • Annual penetration testing. The service is penetration tested at least annually by an independent third party.

How your data is protected

  • Encrypted in transit and at rest using industry-standard encryption.
  • Logically isolated. Your data lives in a dedicated database schema and storage location, encrypted with a key unique to your instance.
  • Data residency. Your data is stored in the region specified in your Order Form, and in the United States if none is specified.
  • You own your data. You retain all right, title and interest in it. We acquire no rights beyond those needed to run the service.

Incident response

We notify you of any security incident without undue delay, and in any event within 24 hours of confirming it. That notice describes what happened, which categories of your data were affected, and what we have done or will do in response. We provide updates as the investigation proceeds, and cooperate with any notification obligations you have under applicable law.

Availability

We commit to 99.5% monthly uptime, excluding scheduled maintenance windows. The full terms, including exclusions, are in §11.4 of our Terms of Service.

Subprocessors

We use subprocessors, including hosting and AI providers, to deliver the service. Each is bound by written agreement to data protection and confidentiality obligations no less protective than our own, and we remain responsible for their performance. A current list is available to customers on request.

HIPAA

OpenGRC is not a general repository for Protected Health Information. Where you are a HIPAA Covered Entity or Business Associate, we offer a Business Associate Agreement (BAA), and the BAA governs the handling of PHI.

Reporting a vulnerability

If you believe you have found a security issue in OpenGRC, please tell us through our contact page. Our machine-readable security contact is published at /.well-known/security.txt.

More detail

Our Trust Center holds current documentation. See also our Privacy Policy and Terms of Service.