generated: '2026-08-12' method: searched probe: true source: https://trust.doit.com/ url: https://trust.doit.com/ provider: Conveyor certifications: - SOC 2 Type 2 - SOC 3 - ISO 27001 - ISO 27001:2022 - GDPR - CCPA - ICO registered - EU-US Data Privacy Framework certification_slugs: - soc2-type-2 - soc3 - iso-27001 - iso-27001-2022 - gdpr - ccpa - ico-registered - eu-us-data-privacy correction_note: An earlier automated keyword sweep of this page also reported HIPAA, FedRAMP, ISO 27017 and ISO 27018. Those strings are present in the page source but belong to OTHER companies' embedded Conveyor trust records (Salesforce), not to DoiT. The list above is taken from the certifications array on the record whose website is https://www.doit.com/ and whose url_addressable_name is "doit". programs: penetration_testing: true bug_bounty: true bug_bounty_url: https://help.doit.com/docs/vendor-information/bug-bounty-program public_subprocessor_list: https://help.doit.com/docs/vendor-information/subprocessors security_policy: https://help.doit.com/docs/vendor-information/security-and-data-access-policy external_services: https://help.doit.com/docs/vendor-information/external-services-we-use reports_available: soc2_type_2: true note: Reports are gated behind a Conveyor NDA/request flow, not published openly. evidence: - source: https://trust.doit.com/ http_status: 200 fetched: '2026-08-12' detail: 'certifications: ["soc2-type-2","iso-27001","gdpr","soc3","ccpa","ico-registered","eu-us-data-privacy","iso-27001-2022"] on the DoiT record' - source: https://www.doit.com/security/ http_status: 200 fetched: '2026-08-12' detail: redirects to https://trust.doit.com/