Skip to content

Security

Enterprise-grade security.
No compromises.

Resultid is built for Fortune 500 data governance requirements, with GDPR compliance, AES-256 encryption, and enterprise-grade access controls. SOC 2 Type II audit in progress.

SOC 2 Type II (In Progress)
GDPR Compliant
TISAX Compliant
AES-256 Encryption
MFA Enabled
Audit Logging

Your data, locked down.

Encryption at rest (AES-256 via AWS KMS) and in transit (TLS 1.2+). All data processed within AWS US infrastructure. Automated data retention and deletion policies with certification of removal.

Who sees what, precisely.

Platform authentication via Amazon Cognito. Role-based access control with granular permissions. Multi-factor authentication required for all accounts. Comprehensive audit logging via AWS CloudTrail with seven-year retention.

Built for enterprise requirements.

GDPR compliant. SOC 2 Type II audit in progress. TISAX label registered and verifiable on the ENX portal. Cleared through Fortune 500 procurement review. Data processing agreements available.

Every byte, encrypted.

  • Encryption at rest: AES-256 via AWS Key Management Service
  • Encryption in transit: TLS 1.2 or higher on all connections
  • Data residency: all data processed within AWS US regions (us-east-1 primary, us-east-2 disaster recovery)
  • Automated retention policies: duration of service plus 90 days, with certification of deletion

Granular control at every level.

  • Authentication: Amazon Cognito with multi-factor authentication required for all accounts
  • RBAC: role-based access down to the data source level
  • Internal SSO: Google Workspace for all internal systems
  • Session management: configurable timeouts, forced re-authentication

Compliance-ready, always.

  • SOC 2 Type II: formal audit in progress with an independent third-party firm
  • GDPR: compliant, with DPA and Standard Contractual Clauses available
  • TISAX: registered label, verifiable by OEMs on the ENX portal
  • CSA CAIQ-Lite: completed cloud security self-assessment
  • Audit logs: immutable record of every action via AWS CloudTrail

Frequently asked questions

Where is my data stored?

All data is processed and stored within AWS infrastructure in the United States (us-east-1 primary region, us-east-2 for disaster recovery). Data never leaves AWS US regions.

What is the status of Resultid's SOC 2 certification?

The formal SOC 2 Type II audit with an independent third-party firm is currently in progress. Our detailed readiness assessment is available under NDA as part of a security review.

Is Resultid GDPR compliant?

Yes. We offer Data Processing Agreements with Standard Contractual Clauses, and your data is never retained or used to train AI models. An AI Automated Decision Making Transparency Notice is also available.

How does Resultid handle data retention?

Customer data is retained for the duration of the service agreement plus 90 days. Upon termination, data is deleted with certification of removal. You can also request data purging at any time.

What sub-processors does Resultid use?

Resultid uses AWS for cloud infrastructure, Amazon SageMaker and Bedrock for AI/ML processing (with zero data retention on model inputs), and standard business tools including Google Workspace, Slack, and GitHub. A full sub-processor list is available in our Data Processing Agreement.

Does Resultid use AI to process customer data?

Yes. Resultid uses proprietary embedding models and AWS AI/ML services (SageMaker, Bedrock) to generate operational intelligence. All AI processing is configured with zero data retention. Model providers do not store or train on your data.

How quickly does Resultid respond to security incidents?

Critical incidents target a 1-hour response time. In the event of a data breach affecting your data, we provide notification within 48 hours as specified in our Data Processing Agreement.

Does Resultid support automotive security requirements?

Yes. Resultid holds a registered TISAX label, which OEMs can verify directly on the ENX portal, and we have been cleared through Fortune 500 automotive procurement review. Contact us for our automotive-specific security documentation.

Next step

Have security questions? Talk to our team.

Your existing data. No new surveys. No integrations. No consultants.

30

days to first insight

0

new data collected

$200M+

surfaced across customers

No integration required · GDPR-compliant · If we can’t show you revenue you didn’t know was there, you’ll know in the first meeting.