Trust centre

How we protect the access you give us

An MDR provider holds the keys to your environment. This page covers where your data lives, who can touch it, what we've certified and what's still in progress.

Last updated 29 September 2026
Compliance status
SOC 2 Type I In progress Audit underway; report expected Q1 2027.
SOC 2 Type II Planned Observation period begins once Type I is issued; report expected Q4 2027.
GDPR & UK GDPR Aligned DPA with standard contractual clauses available.
Where your data lives Customer telemetry is stored in the region you choose (US, UK or EU) and does not leave it. Hosted on IONOS, Microsoft Azure and Google Cloud.
Least-privilege access Analysts use named accounts with phishing-resistant MFA, just-in-time elevation and full session logging. No shared credentials.
Scoped response permissions API permissions are limited to the actions in your response-authority agreement. You can revoke them at any time.
Encryption TLS 1.2+ in transit and AES-256 at rest, with keys managed by our cloud provider’s key service.
Retention and exit Telemetry is kept for 90 days by default. Data linked to a major incident is retained for 13 months to support investigation, insurance and regulatory needs. On exit, you get a full export in open formats and we delete your data within 30 days.
We watch ourselves too Our own environment is monitored by Pulse, with the same detections and SLAs our customers get.
Sub-processors
Third parties that process customer data on our behalf. We give 30 days' notice before adding one.
ProviderPurposeLocation
IONOS, Microsoft Azure, Google Cloud, AWSHosting and storage of platform dataRegion of your choice
MicrosoftEmail and notificationsRegion of your choice
CloudflareWeb protection and bot filtering on public formsGlobal
Documents
Available on request, most under NDA. We usually reply within one business day.
Security overview (PDF)Request → Data processing agreementRequest → Completed security questionnaire (CAIQ)Request → Privacy policyRead → Terms of serviceRead → Cookie policyRead →
Report a vulnerability
Found a security issue in Touchpoint? Email security@tp-security.com. We acknowledge within 2 business days, won't pursue good-faith research, and credit reporters who want it.