Platform / Security & Governance

Built to clear your procurement and your conscience.

Warewink operates inside institutional environments. That means a serious posture on encryption, access, governance, and responsible data use. This page documents what we do, in plain English, with no security theater.

SOC 2 aligned
Controls mapped to SOC 2 Type II criteria, with audit in progress per our published roadmap.
GDPR & CCPA ready
Lawful-basis documentation, data subject request workflow, and a published privacy policy.
ISO 27001 aligned
Information security management practices aligned to ISO 27001 controls.
Audit logs by default
Every read, write, and routing action is logged, retained, and exportable to your SIEM.
01 / Controls

Controls, in detail.

Encryption in transit and at rest

TLS 1.2+ for all transport. AES-256 at rest for stored data. Key rotation on a documented schedule.

SSO and SCIM

SAML and OIDC single sign-on with SCIM provisioning, plus enforced multi-factor authentication for all human accounts.

Role-based access control

Least-privilege roles, scoped per workspace and per data domain, with quarterly access reviews you can audit.

Tenant isolation

Logical isolation between workspaces with no cross-tenant queries. Optional dedicated infrastructure for regulated customers.

Data residency

Choose where your data is processed and stored. Region-pinned deployments available for EU and US workloads.

Incident response

Documented runbooks, on-call rotation, and contractual breach-notification timelines aligned to enterprise procurement.

02 / Responsible use

Our data principles.

A signal engine is only as trustworthy as the discipline behind it. These are the lines we will not cross, written down and enforced contractually.

  • 01
    We collect the minimum data required to detect a signal and route an opportunity. Nothing more.
  • 02
    We do not resell your data, your signals, or any derived insights to another customer.
  • 03
    We do not build shadow profiles of individuals or publish unverified inferences as facts.
  • 04
    We honor data subject requests under GDPR and CCPA, and we pass them through to our subprocessors.
  • 05
    We disclose subprocessors, license terms, and data lineage on request, in writing.