Security at Topiq
Your email, calendar and meetings are some of your most sensitive data. We treat them that way.
This page summarizes how Topiq protects customer data: how it is isolated, encrypted, accessed, monitored and recovered, and which providers process it. If you need more detail, we will complete your organization's security questionnaire or walk your team through our controls on a call.
Security contact: [email protected]
SOC 2 Type II
Audit being scheduled
Controls designed against the SOC 2 Trust Services Criteria.
Penetration testing
Annual, third party
Attestation letter available on request.
Security breaches
None to date
Customers notified within 72 hours of a confirmed breach.
Customer data used to train AI
Never
Pre-trained models only, with zero data retention agreements where available.
Compliance & assurance
Our controls are designed against recognized frameworks today, and we are working toward independent attestation.
SOC 2 Type II
In progressWe are scheduling our SOC 2 Type II audit with an independent audit firm. Our controls already follow the SOC 2 Trust Services Criteria. A Type II audit tests whether those controls operate effectively over a sustained observation period, not just at a single point in time. We will update this page as the audit progresses.
Independent penetration testing
AnnualThird-party security firms test our application and network perimeter at least once a year. The assessments also review security best practices more broadly. We triage findings by severity and remediate them. A penetration test attestation letter is available on request.
Framework alignment
Our Information Security Program follows the SOC 2 Trust Services Criteria, ISO 27001 Annex A and the NIST Cybersecurity Framework. We are not certified against ISO 27001; we use it, alongside the other frameworks, to design and measure our controls.
Security ownership
Our CTO owns security. That covers architecture review, access policy, incident response and vendor risk. A dedicated information security engineer, engaged part time, provides ongoing review and validation of our systems. Our infrastructure runs entirely on AWS, so it also inherits AWS's SOC 2 Type II and ISO 27001 certified physical and infrastructure controls.
How we protect your data
A summary of the controls behind the platform.
Cloud infrastructure & network
- Hosted entirely on AWS (EKS and RDS) in private subnets. No server or database is publicly reachable.
- All inbound traffic passes through AWS WAF and an Nginx ingress layer.
- Service-to-service traffic is encrypted and authenticated with mutual TLS (Linkerd).
- Security groups permit only the ports and sources each service needs.
Encryption & secrets
- TLS on every connection. Non-TLS connections are rejected.
- Databases, object storage and backups are encrypted at rest with AWS KMS-managed keys.
- OAuth tokens are stored in encrypted fields. Internal secrets live in Doppler and are injected at runtime, never stored in code.
- Cryptographic operations use constant-time implementations and secure random number generators.
Tenant isolation & access
- Each customer workspace has its own database schema, and every query is scoped to that workspace.
- Files are stored under non-guessable UUID identifiers and served only through authenticated requests.
- Role-based access is enforced server-side at the route, middleware, controller and query layers. If a check fails, the request is denied.
- Only approved engineers can reach customer data, with temporary access granted only to troubleshoot an issue.
Authentication
- Customers sign in with SSO only, through Google or Microsoft Entra ID (OIDC), so we never store user passwords.
- Every employee account requires MFA, using hardware security keys (FIDO2) or TOTP. SMS is not permitted.
- Sessions are invalidated on logout, and sensitive actions require re-verification.
- No shared or default accounts exist anywhere in the application or infrastructure.
Secure development
- Every change requires peer review. Nobody commits directly to protected branches.
- CodeQL static analysis, secret scanning and Dependabot run automatically on every change.
- Merges are blocked automatically on high-severity findings, and engineers cannot bypass them.
- We deploy only through automated CI/CD, and production artifacts are code-signed.
Monitoring & incident response
- CloudTrail, CloudWatch, VPC Flow Logs, RDS and S3 access logs, plus application audit logs.
- Automated agents analyze logs continuously for anomalies and escalate alerts to senior engineers.
- We follow a documented incident response plan with defined severities. The most severe incidents (P1) get a response within 1 hour.
- Credentials, tokens and personal data are never written to logs.
Backup & resilience
- The production database runs Multi-AZ, with automatic failover to a standby in a separate availability zone.
- Automated daily backups are encrypted with KMS and kept for 7 days.
- Deletion protection guards against accidental data loss.
- Critical and high-severity patches get expedited deployment.
People
- All personnel, including contractors, sign confidentiality agreements and our Acceptable Use Policy.
- Everyone completes security onboarding with our CTO. Engineers also complete secure-coding training.
- All credentials are managed in 1Password, and SSH keys never sit on disk as plaintext.
Endpoints
- Company-issued macOS devices only. Personal devices (BYOD) are not allowed for employees.
- Every device has full-disk encryption, a firewall, auto-lock and automatic security updates enabled.
- Lost or stolen devices can be locked or wiped remotely.
Privacy & responsible AI
AI is central to Topiq. Here is how we keep it from becoming a risk to your data.
Your data stays yours
- You own and control your data. We process it only to provide the service.
- We do not sell personal information, and we never examine customer data without your express permission.
- We honor access and deletion requests, and deletions extend to the subprocessors we control.
- Data is classified into four protection levels (Public, Internal, Confidential, Restricted), each with defined handling requirements.
AI governance
- We use only pre-trained models from established providers (OpenAI, Deepgram). We do no training or fine-tuning on customer data.
- Each request is stateless and contains only the data it needs. Prompts are not logged.
- We hold zero data retention agreements with AI providers where available.
- A formal AI Governance Policy and prompt evaluations guard output quality. AI assists users and never makes autonomous decisions.
Subprocessors
We keep our vendor footprint small. Our CTO approves every provider that touches customer data, after a security review.
| Provider | Purpose | Data handling |
|---|---|---|
| Amazon Web Services | Hosting, database, storage and compute | Processes and stores customer data |
| Email and calendar integration (Google Workspace APIs) | Processes customer data | |
| Microsoft | Email and calendar integration (Microsoft Graph APIs) | Processes customer data |
| OpenAI | AI features: summarization, analysis, smart replies | Processes customer data; zero data retention on API requests |
| Deepgram | Meeting transcription (speech-to-text) | Processes customer data; audio not retained after processing |
| Slack | Messaging integration | Processes customer data |
| Zoom | Meeting integration | Data is received from Zoom only; no customer data is sent to it |
AI processing currently takes place in the United States. All data sent to subprocessors is encrypted in transit.
Security documentation
Our Privacy Policy, Terms of Service and DPA are public. The other documents are available to customers and prospects on request; some may require a mutual NDA.
Penetration test attestation
Summary letter from our most recent third-party test
Information Security Program overview
Governance, risk management and control domains
Security Incident Response Plan
Severity levels, roles and customer notification
Data Classification Policy
Protection levels and the data classification matrix
AI Governance Policy
Provider selection, data handling and responsible use
Your security questionnaire
We are glad to complete your organization's questionnaire
SOC 2 Type II report
Will be available after the audit is complete
Privacy Policy
Terms of Service
Data Processing Addendum (DPA)
Have a question we haven't answered?
Contact us to request documents, report a security concern or set up a call with our CTO. Every customer also has a dedicated account representative.
Email [email protected]
Last updated October 2026. This page summarizes our security practices and does not modify any agreement between Topiq and its customers.