Security and compliance are fundamental to keeping our users data safe, and as such this is a top priority here at involve.me.
SOC 2
SOC 2 is a security audit that evaluates how well a company’s systems are set up at a specific point in time to protect customer data. It’s like a snapshot of the company’s controls and processes on a particular day.
involve.me is SOC2 Type 1 audited and we are currently in our Type 2 audit phase (find the letter of intent in our trust center).
You can see more details about security at involve.me and download the reports and further security related documents in our trust center.
To get access to all compliance documents, an Enterprise plan or signed Enterprise letter of engagement is required.
If you're not yet on an Enterprise plan but you're interested, then make sure to fill out our Enterprise form by clicking here.
GDPR
The GDPR, or General Data Protection Regulation, is a European Union law focused on protecting the personal data of individuals within the EU and the EEA (European Economic Area).
involve.me is fully GDPR compliant. Please read our updated terms and conditions, privacy policy and data processing agreement for more details.
Additionally involve.me offers you the tools to easily create GDPR compliant content, such as customizable checkboxes and legal text suggestions for the services you use.
PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) is a global information security standard developed to protect credit card transactions and cardholder data from fraud and breaches. It applies to all organizations that store, process, or transmit payment card information, ensuring critical security best practices are implemented throughout the payment system.
For our assessment of involve.me, we completed the PCI DSS SAQ A, which is intended for merchants who accept only card-not-present payments and fully outsource cardholder data management to PCI DSS-compliant providers.
As involve.me uses Stripe as its payment gateway, cardholder data is securely processed without being stored, transmitted, or handled by our own systems.
If you have any questions that were not addressed in this article then please contact our support team.