Skip to content

Trust & Security

HarborGuard scans the software supply chain, so we treat our own security posture as a first-class product feature. This section is the public-facing summary that vendor-risk and procurement teams can rely on during due diligence.

HarborGuard is an early-stage product, and this Trust section is an honest snapshot of where we are today rather than a roadmap of where we plan to be. We are not currently engaged in any formal compliance audits and hold no third-party certifications yet. We will update each page as the product matures, audits begin, and certifications are issued — so customers and prospects can follow our progress with confidence.

At a glance

AreaStatus
SOC 2 Type IINot yet pursued — planned as we mature
ISO 27001Not yet pursued — planned as we mature
HIPAA BAA availableNot currently offered
PCI-DSS scopeOut of scope (card data handled by Stripe)
FedRAMPNot pursued
Encryption in transitTLS 1.2+
Encryption at restAES-256-GCM envelope encryption for credentials
Customer data residencyUS (primary)

In this section

Contact

  • Security and disclosure: security@harborguard.co
  • Privacy and DPA requests: privacy@harborguard.co
  • Vendor due diligence: trust@harborguard.co

On this page