> For the complete documentation index, see [llms.txt](https://docs.peig.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.peig.io/trust-center.md).

# Trust Center

**Built on trust. Secured by design.**

This is your centralized resource for understanding how Peig protects your data, ensures platform integrity, and maintains compliance with leading security and privacy standards.

***

### Certifications & Compliance

<table data-view="cards"><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>SOC 2 Type II</strong></td><td>Attested since January 2026. Ongoing commitment to security, availability, and confidentiality.</td></tr><tr><td><strong>ISO 9001:2015</strong></td><td>Quality management system covering the design, development, and delivery of our authentication platform.</td></tr><tr><td><strong>NIST SP 800-63B</strong></td><td>Independently assessed against cryptographic authenticator requirements. Modern, passwordless identity assurance.</td></tr><tr><td><strong>EU GDPR</strong></td><td>Adhering to GDPR requirements for personal data protection and strong privacy practices.</td></tr></tbody></table>

***

### Security Practices

#### How we protect your data

We go beyond industry best practices with advanced security architecture and continuous monitoring across every layer of our platform.

<table data-view="cards"><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Role-based access control</strong></td><td>Strict RBAC ensures privileged users only access resources required for their role.</td></tr><tr><td><strong>Encryption at rest &#x26; in transit</strong></td><td>AES-256 at rest, TLS 1.2/1.3 in transit. Keys managed via dedicated KMS with regular rotation.</td></tr><tr><td><strong>Secure device-bound access</strong></td><td>Peig administrators authenticate via a federated Peig Workspace — aligned with our customer security model.</td></tr><tr><td><strong>Penetration testing</strong></td><td>Regular internal and third-party pen tests, plus continuous scanning for vulnerabilities and CVEs.</td></tr><tr><td><strong>Audit trail &#x26; log retention</strong></td><td>Security-relevant logs retained with defined periods. Real-time monitoring for access anomalies and threats.</td></tr><tr><td><strong>Incident response</strong></td><td>Specialists equipped to detect, triage, contain, eradicate, recover, and notify customers of incidents.</td></tr><tr><td><strong>Backup &#x26; disaster recovery</strong></td><td>Regular backups and periodic DR drills. Documented RTO and RPO with test results reviewed continuously.</td></tr><tr><td><strong>Network security</strong></td><td>Firewalls, network segmentation, and regular hardening reviews. 24/7 production infrastructure monitoring.</td></tr><tr><td><strong>Risk assessment</strong></td><td>Formal risk assessments on a regular basis. Treatment plans tracked and reviewed by management.</td></tr><tr><td><strong>Vendor risk management</strong></td><td>Third-party vendors and subprocessors assessed before onboarding and on an ongoing basis.</td></tr><tr><td><strong>Periodic access reviews</strong></td><td>Regular reviews of user access rights. Access promptly revoked upon role changes or offboarding.</td></tr><tr><td><strong>Change management</strong></td><td>All production changes follow a formal process with clear visibility into modifications, authors, and procedures.</td></tr></tbody></table>

***

### Privacy & Data Protection

#### How we handle your data

Peig Workspace may process limited user profile data (name, email, phone number) for identity management and access control. Peig acts as a **data processor** on behalf of enterprise customers under GDPR. We do not sell personal data, and information is disclosed only to necessary third-party service providers.

Personal data is protected through access controls, logging and monitoring, and encryption in transit. We support the following data subject rights:

* ✅ Right of access
* ✅ Right to rectification
* ✅ Right to erasure
* ✅ Right to data portability
* ✅ Right to object or restrict processing

{% hint style="info" %}
A standard **Data Processing Agreement (DPA)** is available upon request for enterprise customers.
{% endhint %}

***

### Documentation

***

### Contact

{% hint style="success" %}
**Have questions or documentation requests?** Our team is ready to support you with any security or compliance queries.

📧 <trust@peig.io> · PGP key available upon request
{% endhint %}
