Certifications and independent assurance

Independent review of our controls, renewed on a fixed annual cycle rather than a one-time exercise.

SOC 2 Type II

SideDrawer complies with SOC 2 Type II under SSAE-18 standards. The audit evaluates our controls, procedures and documentation against criteria established by the American Institute of Certified Public Accountants (AICPA), and is performed every year by an independent third-party auditor.

Report available under NDA

Cloud Security Alliance

SideDrawer is a Trusted Cloud Provider registrant with the Cloud Security Alliance, the industry body that sets best practice for security assurance in cloud computing.

Trusted Cloud Provider

Third-party penetration testing

SideDrawer engages an independent third-party firm to conduct penetration testing, alongside regular vulnerability scanning of internal networks and systems. Findings are tracked and remediated through our vulnerability management programme.

Independent third party

Annual policy review and audit

Our information security policies are approved by management, published to employees, and reviewed at least every twelve months. A third-party auditor reviews our policies annually.

Reviewed annually

Privacy and regulatory alignment

We maintain policies and procedures designed to meet applicable privacy, regulatory and contractual requirements, including PIPEDA in Canada and GDPR in the European Union. Requirements specific to your jurisdiction or regulator are addressed contractually.

Regulatory alignment

Enterprise identity and access

Single sign-on via SAML and OIDC, integration with Okta and Azure AD, configurable multi-factor authentication with passkey support, and organization-wide MFA enforcement.

SAML · OIDC · passkeys

Control inventory

The controls that protect client documents in SideDrawer, grouped the way a security review reads them. Further detail is available under NDA.

Encryption and key management

  • Data at rest encrypted with AES-256
  • Data in transit protected by TLS 1.2 or higher
  • Encryption applies to data at rest, in transit and while being processed, including uploaded files
  • Key management duties are segregated from access to the data those keys protect

Access control

  • Configurable multi-factor authentication with passkey support, plus FaceID, TouchID, push notification, SMS and email
  • Administrators can enforce MFA across their entire organization
  • Single sign-on via SAML and OIDC, integrating with existing identity providers including Okta and Azure AD
  • Granular role-based access control enforced at both vault and drawer level, per collaborator
  • Identity and Access Management governs request, approval, periodic review and deprovisioning of employee access
  • Employee access is granted by role, restricted to the systems required for the job function

Secure exchange by design

  • No email attachments and no public file-sharing links — documents are exchanged inside the platform, reducing the cyber risk that email-based exchange introduces
  • Every participant is authenticated and permissioned before a document is visible to them
  • API-based architecture, so the same controls apply whether users reach SideDrawer directly or through an embedded client experience

Data protection and audit trail

  • Immutable audit trail — every document interaction, access event and permission change is logged with a timestamp
  • Audit records cannot be altered or deleted by clients, and are available for regulatory examination on request
  • Changes to records are captured through a comprehensive change log
  • Virus and malware scanning runs on every file uploaded, before it reaches a vault
  • Retention and deletion windows are governed by our Data Processing Agreement and confirmed contractually

Platform and architecture

  • Serverless, cloud-based architecture — cloud-agnostic and fully redundant
  • Primary and secondary environments support failover in a business continuity event
  • Infrastructure is provided by global leading cloud providers; their independent SOC reports are obtained and reviewed on a recurring basis

Data residency and hosting

  • Hosted on Amazon Web Services and Microsoft Azure
  • Production regions in Canada and the United States
  • Data residency is configured per client and applied to data at rest; additional regions can be assessed on request where infrastructure can be provisioned
  • Current subprocessor regions are published at /legal/sub-processors

Backup, continuity and recovery

  • Documented Business Continuity Plan and Disaster Recovery Plan
  • Files are replicated and databases are snapshotted and backed up offsite on a defined schedule, supporting our recovery objectives
  • Backups are held across more than one cloud provider, with multiple redundancies
  • Recovery is supported by automated, cloud-native backup and recovery tooling
  • 99.9% target uptime, with an RTO of 2 hours and an RPO of 6 hours

Vulnerability and threat management

  • Documented vulnerability management policy, approved by management and communicated to relevant personnel
  • Third-party penetration testing conducted by an independent firm
  • Regular vulnerability scanning of internal networks and systems, alongside continuous automated scanning
  • Testing methodology draws on recognised standards including OSSTMM, OWASP and NIST SP 800-115
  • Findings are triaged by exploitability and business impact, and tracked to remediation
  • Layered detection across network, endpoint and cloud workloads
  • Internal security staff conduct assessments, with findings reviewed weekly and infrastructure status reported monthly

Incident response

  • Formal, management-approved Incident Response Plan with defined severity tiers
  • Established incident management programme, documented and communicated to relevant personnel
  • Defined escalation procedures with CISO oversight
  • Regular exercises to validate readiness
  • 72-hour breach notification commitment

People and personnel security

  • Criminal background checks form part of pre-employment screening
  • All employees sign and abide by confidentiality agreements, plus internal cybersecurity and privacy policies
  • Formal security training and awareness programme for staff

Governance, risk and compliance

  • Formal, documented security policies, standards, plans and operating procedures
  • Information security policies are approved by management, published to employees, and reviewed at least every twelve months
  • A third-party auditor reviews our policies annually
  • Formally established risk management programme to identify and track risks
  • Internal audit, risk management and compliance oversight for identifying and tracking resolution of outstanding regulatory issues
  • Documented operational change management policy, approved by management and communicated to relevant personnel
  • CISO-level ownership of the information security programme, supported by our Chief Security Advisor
  • Subprocessors published and maintained at /legal/sub-processors

Documents and policies

What exists, and how to get it. Documentation under NDA is released to clients and to prospective clients in an active evaluation.

DocumentAvailability
SOC 2 Type II reportUnder NDA
Data Processing AgreementPublic  View
Privacy PolicyPublic  View
Terms of UsePublic  View
Subprocessor listPublic  View

Additional detail beyond what is published here can be provided under NDA.

Questions security teams ask

If your review needs something that is not answered here, request our documentation and we will route it to our security team. Additional detail can be provided under NDA.

Yes. SideDrawer complies with SOC 2 Type II under SSAE-18 standards, audited every year by an independent third-party auditor against criteria established by the AICPA. The report is available to clients and prospective clients under NDA.
Yes. SideDrawer is a Trusted Cloud Provider registrant with the Cloud Security Alliance.
Yes. An independent third-party firm conducts penetration testing, and we run regular vulnerability scans against internal networks and systems alongside continuous automated scanning. Our methodology draws on recognised standards including OSSTMM, OWASP and NIST SP 800-115.
Yes. Our information security policies are approved by management, published to employees, and reviewed at least every twelve months — they are living documents, monitored and updated as the threat and regulatory landscape changes. A third-party auditor reviews our policies annually.
SideDrawer runs a serverless, cloud-based architecture. It is cloud-agnostic and fully redundant, hosted on Amazon Web Services and Microsoft Azure.
Production regions are in Canada and the United States, across AWS and Azure. Data residency is configured per client and applies to data at rest, so it can be set to meet your regulator’s requirements. Additional regions can be assessed on request where infrastructure can be provisioned. Our current subprocessor list is published at /legal/sub-processors.
We target 99.9% uptime, a Recovery Time Objective that will not exceed 2 hours, and a Recovery Point Objective that will not exceed 6 hours. Live service availability is published at status.sidedrawer.com, and the commitments applicable to your agreement are confirmed contractually.
Files are replicated, and databases are snapshotted and backed up offsite on a defined schedule that supports the recovery objectives above. Backups are held across more than one cloud provider with multiple redundancies.
Yes. Both a Business Continuity Plan and a Disaster Recovery Plan are documented, and we maintain primary and secondary environments to support failover in a continuity event. Both plans are available under NDA.
Without undue delay, and in any event within 72 hours of confirming a personal data breach. This is a commitment in our Data Processing Agreement, not a target. We also maintain mechanisms to notify affected clients of suspected or actual fraudulent activity.
All customer personal data is deleted within 20 business days of the service ending. If you ask for it back before then, it is returned within 10 business days. Retention windows during the term are governed by our Data Processing Agreement.
Yes. Our Data Processing Agreement provides for one audit per calendar year, plus any audit mandated by your regulator, conducted during business hours with NDA-bound auditors.
Yes. Every document interaction, access event and permission change is logged with a timestamp. Those records cannot be altered or deleted by clients, and are available for regulatory examination on request.
Yes to both. SideDrawer supports single sign-on via SAML and OIDC and integrates with existing identity providers including Okta and Azure AD. Multi-factor authentication is configurable, supports passkeys, and an administrator can enforce it across your entire organization.
Pre-employment screening includes criminal background checks. All employees sign and abide by confidentiality agreements as well as internal cybersecurity and privacy policies, and we run a formal security training and awareness programme. Employee access is granted by role and limited to the systems required for the job.

Need something for your review?

Tell us what your security or procurement team needs and we will route the request to our security team. Additional detail beyond this page can be provided under NDA. Live service availability is published at status.sidedrawer.com.

Last reviewed: 2 September 2026