Trust Center
Security, privacy and compliance evidence for teams evaluating SideDrawer. We are SOC 2 Type II compliant under SSAE-18 and a Trusted Cloud Provider registrant with the Cloud Security Alliance. This page is public; our full documentation set, including the SOC 2 Type II report, is available to clients and prospective clients under NDA.
Certifications and independent assurance
Independent review of our controls, renewed on a fixed annual cycle rather than a one-time exercise.
SOC 2 Type II
SideDrawer complies with SOC 2 Type II under SSAE-18 standards. The audit evaluates our controls, procedures and documentation against criteria established by the American Institute of Certified Public Accountants (AICPA), and is performed every year by an independent third-party auditor.
Report available under NDACloud Security Alliance
SideDrawer is a Trusted Cloud Provider registrant with the Cloud Security Alliance, the industry body that sets best practice for security assurance in cloud computing.
Trusted Cloud ProviderThird-party penetration testing
SideDrawer engages an independent third-party firm to conduct penetration testing, alongside regular vulnerability scanning of internal networks and systems. Findings are tracked and remediated through our vulnerability management programme.
Independent third partyAnnual policy review and audit
Our information security policies are approved by management, published to employees, and reviewed at least every twelve months. A third-party auditor reviews our policies annually.
Reviewed annuallyPrivacy and regulatory alignment
We maintain policies and procedures designed to meet applicable privacy, regulatory and contractual requirements, including PIPEDA in Canada and GDPR in the European Union. Requirements specific to your jurisdiction or regulator are addressed contractually.
Regulatory alignmentEnterprise identity and access
Single sign-on via SAML and OIDC, integration with Okta and Azure AD, configurable multi-factor authentication with passkey support, and organization-wide MFA enforcement.
SAML · OIDC · passkeysControl inventory
The controls that protect client documents in SideDrawer, grouped the way a security review reads them. Further detail is available under NDA.
Encryption and key management
- Data at rest encrypted with AES-256
- Data in transit protected by TLS 1.2 or higher
- Encryption applies to data at rest, in transit and while being processed, including uploaded files
- Key management duties are segregated from access to the data those keys protect
Access control
- Configurable multi-factor authentication with passkey support, plus FaceID, TouchID, push notification, SMS and email
- Administrators can enforce MFA across their entire organization
- Single sign-on via SAML and OIDC, integrating with existing identity providers including Okta and Azure AD
- Granular role-based access control enforced at both vault and drawer level, per collaborator
- Identity and Access Management governs request, approval, periodic review and deprovisioning of employee access
- Employee access is granted by role, restricted to the systems required for the job function
Secure exchange by design
- No email attachments and no public file-sharing links — documents are exchanged inside the platform, reducing the cyber risk that email-based exchange introduces
- Every participant is authenticated and permissioned before a document is visible to them
- API-based architecture, so the same controls apply whether users reach SideDrawer directly or through an embedded client experience
Data protection and audit trail
- Immutable audit trail — every document interaction, access event and permission change is logged with a timestamp
- Audit records cannot be altered or deleted by clients, and are available for regulatory examination on request
- Changes to records are captured through a comprehensive change log
- Virus and malware scanning runs on every file uploaded, before it reaches a vault
- Retention and deletion windows are governed by our Data Processing Agreement and confirmed contractually
Platform and architecture
- Serverless, cloud-based architecture — cloud-agnostic and fully redundant
- Primary and secondary environments support failover in a business continuity event
- Infrastructure is provided by global leading cloud providers; their independent SOC reports are obtained and reviewed on a recurring basis
Data residency and hosting
- Hosted on Amazon Web Services and Microsoft Azure
- Production regions in Canada and the United States
- Data residency is configured per client and applied to data at rest; additional regions can be assessed on request where infrastructure can be provisioned
- Current subprocessor regions are published at /legal/sub-processors
Backup, continuity and recovery
- Documented Business Continuity Plan and Disaster Recovery Plan
- Files are replicated and databases are snapshotted and backed up offsite on a defined schedule, supporting our recovery objectives
- Backups are held across more than one cloud provider, with multiple redundancies
- Recovery is supported by automated, cloud-native backup and recovery tooling
- 99.9% target uptime, with an RTO of 2 hours and an RPO of 6 hours
Vulnerability and threat management
- Documented vulnerability management policy, approved by management and communicated to relevant personnel
- Third-party penetration testing conducted by an independent firm
- Regular vulnerability scanning of internal networks and systems, alongside continuous automated scanning
- Testing methodology draws on recognised standards including OSSTMM, OWASP and NIST SP 800-115
- Findings are triaged by exploitability and business impact, and tracked to remediation
- Layered detection across network, endpoint and cloud workloads
- Internal security staff conduct assessments, with findings reviewed weekly and infrastructure status reported monthly
Incident response
- Formal, management-approved Incident Response Plan with defined severity tiers
- Established incident management programme, documented and communicated to relevant personnel
- Defined escalation procedures with CISO oversight
- Regular exercises to validate readiness
- 72-hour breach notification commitment
People and personnel security
- Criminal background checks form part of pre-employment screening
- All employees sign and abide by confidentiality agreements, plus internal cybersecurity and privacy policies
- Formal security training and awareness programme for staff
Governance, risk and compliance
- Formal, documented security policies, standards, plans and operating procedures
- Information security policies are approved by management, published to employees, and reviewed at least every twelve months
- A third-party auditor reviews our policies annually
- Formally established risk management programme to identify and track risks
- Internal audit, risk management and compliance oversight for identifying and tracking resolution of outstanding regulatory issues
- Documented operational change management policy, approved by management and communicated to relevant personnel
- CISO-level ownership of the information security programme, supported by our Chief Security Advisor
- Subprocessors published and maintained at /legal/sub-processors
Documents and policies
What exists, and how to get it. Documentation under NDA is released to clients and to prospective clients in an active evaluation.
| Document | Availability |
|---|---|
| SOC 2 Type II report | Under NDA |
| Data Processing Agreement | Public View |
| Privacy Policy | Public View |
| Terms of Use | Public View |
| Subprocessor list | Public View |
Additional detail beyond what is published here can be provided under NDA.
Questions security teams ask
If your review needs something that is not answered here, request our documentation and we will route it to our security team. Additional detail can be provided under NDA.
Need something for your review?
Tell us what your security or procurement team needs and we will route the request to our security team. Additional detail beyond this page can be provided under NDA. Live service availability is published at status.sidedrawer.com.
Last reviewed: 2 September 2026