Security & Compliance
Our Commitment
ThreatMate runs a security program built to protect the confidentiality, integrity, and availability of customer data. We hold our own systems to the same standard we help MSPs enforce for their clients.
Last reviewed: June 2026
Independent Attestation
SOC 2 Type II
Independently audited controls for security, availability, and confidentiality. Full report available under NDA.
Request SOC 2 ReportOur Security Posture
The internal controls that keep ThreatMate itself secure.
Multi-Factor Authentication (MFA)
MFA is enforced on all internal systems and on every login to the ThreatMate platform.
Role-Based Access Controls (RBAC)
Internal access to systems and customer data is scoped to least privilege and reviewed regularly.
Encryption at Rest and in Transit
All customer data we hold is encrypted in storage and in transit using industry-standard algorithms.
Vulnerability Scanning & Penetration Testing
We continuously scan and regularly pentest our own infrastructure, then remediate findings on internal SLAs.
Third-Party Risk Management
We vet the vendors and subprocessors that touch our systems, with ongoing review of their security posture.
Protecting Your Environment
What ThreatMate guarantees when you connect it to your client environments.
- Secure OAuth consent with least-privilege scopes for M365 and cloud assessments
- No persistent storage of client credentials
- Safe, controlled, non-destructive automated pentesting techniques
- Multi-tenant isolation between MSPs and between each MSP's clients
- Complete audit trails for all assessment activity
- Sign in with Microsoft (OIDC via Microsoft Entra ID) is supported. All platform access requires multi-factor authentication.
Subprocessors & Data Handling
How we engage third parties, where data lives, and how long it is kept.
Subprocessors
ThreatMate uses a small number of vetted third-party providers to deliver the service. We review each provider's security posture before onboarding and limit them to the minimum data required.
| Subprocessor | Purpose | Data Accessed | Location |
|---|---|---|---|
| Google Cloud Platform | Hosting and infrastructure for all platform, scan, and assessment data | Platform and findings data | US (Northern Virginia) |
| Pendo | Product analytics | Usage events and page views | United States |
| Mailchimp | Marketing email campaigns | Contact names and email addresses | United States |
| Twilio SendGrid | Transactional and alert email delivery | Recipient email address, notification content | United States |
| HubSpot | Customer relationship management | Account and contact data (business name, contact names, email addresses) | United States |
We provide advance notice of any new subprocessor that processes customer data.
Data Residency
All platform data, including scan results and assessment findings, is hosted on Google Cloud Platform in the US (Northern Virginia) region. Customer data is not stored outside this environment.
Data Segregation
ThreatMate is a multi-tenant platform with logical isolation between every MSP and, beneath that, between each of an MSP's client tenants. One customer's data is never accessible to another.
Data Retention & Deletion
Active platform data is retained for the life of the subscription. On termination, active customer data is deleted within 30 days. Residual copies may persist in encrypted backups, which expire on a rolling cycle of up to four months, after which they are permanently purged. Customers may request deletion of specific data during the subscription, fulfilled within 30 days. On offboarding, customer data is rendered permanently unreadable and unrecoverable, and a certificate of secure disposal is available on request.
Access & Confidentiality
Access to customer data is strictly limited to ThreatMate personnel on a need-to-know basis, and all such personnel are bound by enforceable confidentiality obligations.
Incident Response
In the event of a confirmed security incident affecting customer data, we notify affected customers without undue delay and provide written notice within 48 hours.
ThreatMate is built by operators who hold their own systems to the standard they sell. The controls we ship to MSPs are the same ones we run internally, every day.
Contact & Transparency
One path for all security questionnaires, RFIs, RFPs, and concerns.
Security Contact
For security questionnaires, RFIs, RFPs, completed documentation requests, and any security concern, email our security team.
security@threatmate.comSee how ThreatMate identifies and prioritizes risk for MSPs
15 minutes. No pressure. See how ThreatMate identifies and prioritizes risk for multi-tenant MSP operations.