Security & Compliance

    Security & Compliance

    Our Commitment

    ThreatMate runs a security program built to protect the confidentiality, integrity, and availability of customer data. We hold our own systems to the same standard we help MSPs enforce for their clients.

    Last reviewed: June 2026

    Independent Attestation

    SOC 2 Type II

    Independently audited controls for security, availability, and confidentiality. Full report available under NDA.

    Request SOC 2 Report

    Our Security Posture

    The internal controls that keep ThreatMate itself secure.

    Multi-Factor Authentication (MFA)

    MFA is enforced on all internal systems and on every login to the ThreatMate platform.

    Role-Based Access Controls (RBAC)

    Internal access to systems and customer data is scoped to least privilege and reviewed regularly.

    Encryption at Rest and in Transit

    All customer data we hold is encrypted in storage and in transit using industry-standard algorithms.

    Vulnerability Scanning & Penetration Testing

    We continuously scan and regularly pentest our own infrastructure, then remediate findings on internal SLAs.

    Third-Party Risk Management

    We vet the vendors and subprocessors that touch our systems, with ongoing review of their security posture.

    Protecting Your Environment

    What ThreatMate guarantees when you connect it to your client environments.

    • Secure OAuth consent with least-privilege scopes for M365 and cloud assessments
    • No persistent storage of client credentials
    • Safe, controlled, non-destructive automated pentesting techniques
    • Multi-tenant isolation between MSPs and between each MSP's clients
    • Complete audit trails for all assessment activity
    • Sign in with Microsoft (OIDC via Microsoft Entra ID) is supported. All platform access requires multi-factor authentication.

    Subprocessors & Data Handling

    How we engage third parties, where data lives, and how long it is kept.

    Subprocessors

    ThreatMate uses a small number of vetted third-party providers to deliver the service. We review each provider's security posture before onboarding and limit them to the minimum data required.

    SubprocessorPurposeData AccessedLocation
    Google Cloud PlatformHosting and infrastructure for all platform, scan, and assessment dataPlatform and findings dataUS (Northern Virginia)
    PendoProduct analyticsUsage events and page viewsUnited States
    MailchimpMarketing email campaignsContact names and email addressesUnited States
    Twilio SendGridTransactional and alert email deliveryRecipient email address, notification contentUnited States
    HubSpotCustomer relationship managementAccount and contact data (business name, contact names, email addresses)United States

    We provide advance notice of any new subprocessor that processes customer data.

    Data Residency

    All platform data, including scan results and assessment findings, is hosted on Google Cloud Platform in the US (Northern Virginia) region. Customer data is not stored outside this environment.

    Data Segregation

    ThreatMate is a multi-tenant platform with logical isolation between every MSP and, beneath that, between each of an MSP's client tenants. One customer's data is never accessible to another.

    Data Retention & Deletion

    Active platform data is retained for the life of the subscription. On termination, active customer data is deleted within 30 days. Residual copies may persist in encrypted backups, which expire on a rolling cycle of up to four months, after which they are permanently purged. Customers may request deletion of specific data during the subscription, fulfilled within 30 days. On offboarding, customer data is rendered permanently unreadable and unrecoverable, and a certificate of secure disposal is available on request.

    Access & Confidentiality

    Access to customer data is strictly limited to ThreatMate personnel on a need-to-know basis, and all such personnel are bound by enforceable confidentiality obligations.

    Incident Response

    In the event of a confirmed security incident affecting customer data, we notify affected customers without undue delay and provide written notice within 48 hours.

    ThreatMate is built by operators who hold their own systems to the standard they sell. The controls we ship to MSPs are the same ones we run internally, every day.

    Contact & Transparency

    One path for all security questionnaires, RFIs, RFPs, and concerns.

    Security Contact

    For security questionnaires, RFIs, RFPs, completed documentation requests, and any security concern, email our security team.

    security@threatmate.com
    Schedule Your Demo

    See how ThreatMate identifies and prioritizes risk for MSPs

    15 minutes. No pressure. See how ThreatMate identifies and prioritizes risk for multi-tenant MSP operations.