Your data, locked down.
Encryption at rest (AES-256 via AWS KMS) and in transit (TLS 1.2+). All data processed within AWS US infrastructure. Automated data retention and deletion policies with certification of removal.
Who sees what, precisely.
Platform authentication via Amazon Cognito. Role-based access control with granular permissions. Multi-factor authentication required for all accounts. Comprehensive audit logging via AWS CloudTrail with seven-year retention.
Built for enterprise requirements.
GDPR compliant (41/41 requirements). SOC 2 Type II audit in progress with 97% readiness. ISO 27001 aligned. TISAX compliance for automotive clients. Data processing agreements available.
Every byte, encrypted.
- Encryption at rest: AES-256 via AWS Key Management Service
- Encryption in transit: TLS 1.2 or higher on all connections
- Data residency: all data processed within AWS US regions (us-east-1 primary, us-east-2 disaster recovery)
- Automated retention policies: duration of service plus 90 days, with certification of deletion
Granular control at every level.
- Authentication: Amazon Cognito with multi-factor authentication required for all accounts
- RBAC: role-based access down to the data source level
- Internal SSO: Google Workspace for all internal systems
- Session management: configurable timeouts, forced re-authentication
Compliance-ready, always.
- SOC 2 Type II: 97% readiness (37/38 criteria), formal audit in progress
- GDPR: full compliance (41/41 requirements), DPA and Standard Contractual Clauses available
- ISO 27001: aligned controls with compliance checklist maintained
- TISAX: compliance checklist maintained for automotive industry requirements
- CSA CAIQ-Lite: completed cloud security self-assessment
- Audit logs: immutable record of every action via AWS CloudTrail
- Designated Data Protection Officer on staff
Frequently asked questions
Where is my data stored?
All data is processed and stored within AWS infrastructure in the United States (us-east-1 primary region, us-east-2 for disaster recovery). Data never leaves AWS US regions.
What is the status of Resultid's SOC 2 certification?
Resultid has completed a comprehensive SOC 2 Type II readiness assessment, meeting 37 of 38 criteria (97%). The formal Type II audit with an independent third-party firm is currently in progress.
Is Resultid GDPR compliant?
Yes. Resultid meets all 41 GDPR requirements (100% compliance). We offer Data Processing Agreements with Standard Contractual Clauses, and have a designated Data Protection Officer. An AI Automated Decision Making Transparency Notice is also available.
How does Resultid handle data retention?
Customer data is retained for the duration of the service agreement plus 90 days. Upon termination, data is deleted with certification of removal. You can also request data purging at any time.
What sub-processors does Resultid use?
Resultid uses AWS for cloud infrastructure, Amazon SageMaker and Bedrock for AI/ML processing (with zero data retention on model inputs), and standard business tools including Google Workspace, Slack, and GitHub. A full sub-processor list is available in our Data Processing Agreement.
Does Resultid use AI to process customer data?
Yes. Resultid uses proprietary embedding models and AWS AI/ML services (SageMaker, Bedrock) to generate operational intelligence. All AI processing is configured with zero data retention. Model providers do not store or train on your data.
How quickly does Resultid respond to security incidents?
Critical incidents target a 1-hour response time. In the event of a data breach affecting your data, we provide notification within 48 hours as specified in our Data Processing Agreement.
Does Resultid support automotive security requirements?
Yes. Resultid maintains a TISAX compliance checklist and meets the security requirements expected by major automotive OEMs. Contact us for our automotive-specific security documentation.
Next step
Have security questions? Talk to our team.
Your existing data. No new surveys. No integrations. No consultants.
30
days to first insight
0
new data collected
$107M+
surfaced at one OEM
No integration required · GDPR-compliant · If we can’t show you revenue you didn’t know was there, you’ll know in the first meeting.