Trust & compliance
Security posture, spelled out.
The compliance posture Nightglass ships under, in the same shape the FAQ opens with but with the answers behind every badge — independent audits, data residency, sub-processor transparency, and the BAA / single-tenant controls the Enterprise tier unlocks.
SOC 2 Type II
ISO 27001
HIPAA · BAA
EU residency
What the badges mean in practice
Four pillars, audited.
Every badge above earns its place on a single grid below — the audit, the residency, the sub-processor list, and the BAA plus single-tenant controls the Enterprise tier unlocks.
Independent audits
SOC 2 Type II and ISO 27001 reports are available under NDA. The same controls that survived the audit gate the auto-PR path the desk uses to open fixes — the on-call review on top of the same evidence pack we hand to auditors, in the same shape.
Data residency
EU customers pin signals and postmortems to our Frankfurt region; US customers pin to Virginia. Region selection is a tenant setting, not a sales-engineering project — flip it on day one and the desk routes the same way the rest of your stack already does.
Sub-processor transparency
The sub-processor list and a current evidence pack are both available on request. Every integration the desk talks to — alert sources, Git hosts, chat platforms — is named, scoped, and on a page your security team can audit without a sales call in the loop.
BAA & enterprise controls
HIPAA coverage sits on the Enterprise tier today, behind a signed Business Associate Agreement. Single-tenant deploy behind your VPC is part of the same tier — your data, your perimeter, the desk running on your infrastructure rather than ours.
Bring Nightglass into the rotation
The desk ships with the evidence pack.
Join the waitlist and we will share the SOC 2 / ISO 27001 reports under NDA, or skip the queue and book a working session with the team that builds it.
next step
Request the evidence pack.
NDA-ready reports delivered to your security team on request.
Join the Nightglass listRequest a demo