Everything procurement, legal, and security teams ask for — in one place. For anything not listed, contact us.
Standard processor obligations covering GDPR, UK GDPR, and CCPA. Pre-signed by Lepta — counter-sign and return.
Live list of every third-party processor we share Customer Data with, plus the regions and purpose.
How we handle personal information for visitors, accounts, and customers.
Our SOC 2 controls, encryption, key management, retention, and incident-response practices.
Available under NDA. Request via our contact form and we'll send the latest report within 1 business day.
Latest third-party pentest report, available under NDA.
HIPAA BAA, custom DPA terms, vendor-onboarding questionnaires (CAIQ, SIG Lite), regional data-residency commitments, and Enterprise redlines are all handled directly by our security team. Send us a note via the contact form and we'll respond within 1 business day.