generated: '2026-08-13' method: searched probe: true url: https://www.blueconic.com/trust-center title: Security & Trust Center description: >- BlueConic publishes a Security & Trust Center at www.blueconic.com/trust-center, linked from the site header and footer. There is no trust.blueconic.com or security.blueconic.com subdomain — both failed to resolve on 2026-08-13 — and no automated trust-portal (Vanta, Drata, SafeBase) instance; the page is a hand-written control narrative. certifications: - SOC 2 Type 2 - TRUSTe Verified Privacy Seal - TRUSTe Verified International Privacy Seal - EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF) certification_detail: - name: SOC 2 Type 2 scope: Security, Availability, and Confidentiality Trust Services Criteria (AICPA) report_access: Available to customers on request via the sales representative or account team. verbatim: >- "BlueConic has completed a SOC 2 Type 2 audit for the Security, Availability, and Confidentiality Trust Services Criteria." - name: TRUSTe Verified Privacy Seal validation: https://privacy.truste.com/privacy-seal/validation?rid=8b1e2c0e-4547-4a9d-b9b6-fc5975da4b26 - name: EU-U.S. Data Privacy Framework source: https://www.blueconic.com/legal/privacy-policy verbatim: >- "BlueConic has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles." controls: hosting: Amazon Web Services public cloud; multi-tier architecture segregating application systems from the public internet; private subnets behind a load balancer; firewall and routing restrictions on all network access. encryption_in_transit: HTTPS-only user interface; TLS 1.2 and 1.3 with keys of at least 128 bits; SFTP supported for third-party transfers. encryption_at_rest: AES-256 for customer data including backups; user-supplied remote-system credentials encrypted with a 256-bit key. authentication: Username, password and multi-factor authentication; enforced length/complexity/expiration; salted password hashes; SAML SSO integration; automatic session logout. secure_development: SDLC with security and privacy considerations, design and code review, unit and integration testing, recurring OWASP Top Ten secure-coding training. vulnerability_testing: SAST, SCA and DAST integrated into the SDLC; regular third-party platform vulnerability and penetration testing; risk/severity-based remediation; customer pen tests permitted with advance permission. availability: Redundant service clusters across multiple AWS Availability Zones; Business Continuity and Disaster Recovery program with frequent tests; live status at status.blueconic.com. incident_response: 24x7 security monitoring with automated alerting; documented Security Incident Response Plan covering roles, responsibilities and procedures. personnel: Background checks (education, employment, criminal history where lawful); written acknowledgement of data-protection responsibilities; least-privilege access with regular reviews and prompt revocation; mandatory security training. vulnerability_disclosure: security@blueconic.com — see security/blueconic-vulnerability-disclosure.yml. related: privacy_policy: https://www.blueconic.com/legal/privacy-policy terms: https://www.blueconic.com/legal/terms permission_settings: https://www.blueconic.com/legal/permission-settings disclaimer: https://www.blueconic.com/legal/disclaimer status_page: https://status.blueconic.com data_security_and_privacy_overview: https://support.blueconic.com/en/articles/247524-blueconic-data-security-and-privacy-overview evidence: - source: https://www.blueconic.com/trust-center http_status: 200 keywords: [soc 2 type 2, truste, trust center, aes-256, tls 1.2, incident response, penetration testing] - source: https://www.blueconic.com/legal/privacy-policy http_status: 200 keywords: [eu-u.s. data privacy framework, swiss-u.s. dpf, gdpr] negative_probes: - url: https://trust.blueconic.com status: 000 note: DNS did not resolve. - url: https://security.blueconic.com status: 000 note: DNS did not resolve. - url: https://www.blueconic.com/security status: 404 - url: https://www.blueconic.com/compliance status: 404 checked: '2026-08-13'