How we protect your data
A truthful overview of the security posture built into GRC Oversight today. We describe only what the product actually does. No certifications or compliance attestations we don't hold.
Security built into the platform
Encryption of credentials at rest
Append-only audit logging
Hashed authentication
Passive public scanner
Least-privilege data access
Our own live Trust Center
We don't just describe our posture here. We publish it through the same Trust Center product every customer gets. GRC Oversight is our own first tenant.
The page at /trust/grc-oversight is generated by our real trust-center code path, not a hand-built marketing page. It states plainly what we do and don't hold today, including that we have no third-party certifications yet.
View our live Trust Center →Curious what our own site looks like through the free scanner? We haven't published a canned result. Run it yourself and see the same real-time output every visitor gets.
Scan grcoversight.com yourself →What our free scanner sees, in aggregate
Real, aggregated results from our free public scanner, not a security certification, just what's publicly observable. Nightly snapshot, self-selected sample.
Across 10 scanned public sites, 0% are missing DMARC and 0% are missing HSTS.
See the full benchmark reportWhat we don't claim
We do not currently hold any third-party security certification (e.g. SOC 2, ISO 27001). As compliance milestones are reached, we will document them in the Trust Center with evidence.
Reporting a vulnerability
If you believe you've found a security issue, we want to hear from you. Please report it responsibly and give us reasonable time to remediate before public disclosure.
- Email: [email protected]
- Phone: 800-710-7714
- Machine-readable policy: /.well-known/security.txt (RFC 9116)
- Trust details and posture: Trust Center
See how we operationalize trust
Get a guided demo, or start by scanning any domain for free.