Security & Compliance
Security and compliance at ClonePartner
Certifications and security program overview.
- Controls
- 118
- Certifications
- 05
- Subprocessors
- 13
SOC 2 Type II observation period underway
ClonePartner has entered the observation period for its fourth consecutive SOC 2 Type II audit, conducted by our independent auditor, Prescient Security. The audit evaluates the operating effectiveness of our security controls across the observation window, with the renewed report available to customers under NDA on completion.
SOC 2 Type II
● ActiveFeb 1, 2026 → Jan 31, 2027
ISO 27001
● ActiveJul 1, 2024 → Jun 30, 2027
GDPR
● ActiveActive
HIPAA
● ActiveActive
CASA Type II
● ActiveActive
- Single Sign-On (SSO)Enterprise SSO via SAML and OIDC so teams authenticate through their own identity provider.
- Two-Factor Authentication (2FA)Multi-factor authentication enforced for privileged and administrative access.
- Role-Based Access Control (RBAC)Least-privilege, role-based permissions across the platform.
- AES-256 Encryption at RestAll data at rest is encrypted with AES-256.
- Latest TLS in TransitAll data in transit is encrypted with the latest TLS (1.2+).
- Data SovereigntyChoose the region where your data is stored and processed so it stays within your required jurisdiction.
| Name | Purpose | Location |
|---|---|---|
Anthropic | Foundation-model provider reached via Cursor, under the same no-training, limited-retention terms | United States |
Cal.com | Scheduling and calendar management for support sessions | United States |
Cloudflare | Content delivery, DNS, and edge security | Global edge network (HQ: United States) |
Cursor (Anysphere, Inc.) | AI-assisted engineering tooling — privacy mode enforced, no model training, zero- or limited-retention | United States |
DigitalOcean | Hosting, infrastructure and database services | Customers' Designated Region |
Google | Foundation-model provider reached via Cursor, under the same no-training, limited-retention terms | United States |
Google Workspace | Business email, documents, and internal collaboration | United States / EU |
OVHcloud | Cloud infrastructure and compute services | Customers' Designated Region |
OpenAI | Foundation-model provider reached via Cursor, under the same no-training, limited-retention terms | United States |
Resend | Transactional email delivery | United States |
Slack | Team and customer-channel communications | United States |
Tally.so | Form and survey capture for intake and feedback | Belgium (EU) |
Truto | Unified API framework powering internal orchestration | United States |
- Purpose
- Foundation-model provider reached via Cursor, under the same no-training, limited-retention terms
- Location
- United States
- Purpose
- Scheduling and calendar management for support sessions
- Location
- United States
- Purpose
- Content delivery, DNS, and edge security
- Location
- Global edge network (HQ: United States)
- Purpose
- AI-assisted engineering tooling — privacy mode enforced, no model training, zero- or limited-retention
- Location
- United States
- Purpose
- Hosting, infrastructure and database services
- Location
- Customers' Designated Region
- Purpose
- Foundation-model provider reached via Cursor, under the same no-training, limited-retention terms
- Location
- United States
- Purpose
- Business email, documents, and internal collaboration
- Location
- United States / EU
- Purpose
- Cloud infrastructure and compute services
- Location
- Customers' Designated Region
- Purpose
- Foundation-model provider reached via Cursor, under the same no-training, limited-retention terms
- Location
- United States
- Purpose
- Transactional email delivery
- Location
- United States
- Purpose
- Team and customer-channel communications
- Location
- United States
- Purpose
- Form and survey capture for intake and feedback
- Location
- Belgium (EU)
- Purpose
- Unified API framework powering internal orchestration
- Location
- United States
01Is our data safe during a migration?
Yes. Migrations are engineer-led with data encrypted in transit (TLS 1.2+) and at rest (AES-256), least-privilege access for our engineers, and field-level validation on every record — backed by our zero-downtime, zero-data-loss approach.
02Does ClonePartner keep our data after the project ends?
No. Once a migration or engagement completes, Customer Data is deleted within a commercially reasonable period in line with our retention policy. Certified deletion is available on written request.
03Which compliance standards does ClonePartner meet?
ClonePartner maintains SOC 2 Type II and ISO 27001, and complies with HIPAA and GDPR. Detailed documentation, including our ISO certificate and SOC 2 report, is available under NDA via legal@clonepartner.com.
04Can we sign a DPA before migrating?
Absolutely. Our Data Processing Agreement — including the EU and UK Standard Contractual Clauses — is published at clonepartner.com/dpa, and a signed copy is available on request to legal@clonepartner.com.
05Who are your subprocessors?
We use DigitalOcean and OVHcloud for infrastructure, Cal.com and Tally.so for scheduling and intake, and Truto for integration orchestration. All are listed in Schedule C of our DPA and in the Subprocessors section above.
06What happens if there is a data breach?
We notify affected customers without undue delay and, where feasible, within 48 hours of becoming aware of a breach, and cooperate fully on investigation, mitigation, and any regulatory notifications.
- GDPR Compliance CertificateRequest
- HIPAA Compliance CertificateRequest
- ISO 27001 CertificateRequest
- Penetration Test SummaryRequest
- SOC 2 Type II ReportRequest
The information-security policies behind our program. Documents are shared on request — submit a request and we’ll send a secure link once approved.
- Acceptable Use PolicyRequestISMS · v2.0
- Access Control PolicyRequestISMS · v2.1
- Application Security PolicyRequestSecurity · v1.1
- Asset Management PolicyRequestISMS · v1.3
- Business Continuity & Disaster Recovery PlanRequestOperations · v1.3
- Change Management PolicyRequestOperations · v1.3
- Code of Business ConductRequestPeople · v1.4
- Cryptography & Key Management PolicyRequestSecurity · v1.2
- Data Backup PolicyRequestOperations · v1.3
- Data Classification & Handling PolicyRequestPrivacy · v1.2
- Data Protection & Privacy PolicyRequestPrivacy · v2.0
- Data Retention & Disposal PolicyRequestPrivacy · v1.1
- Endpoint & Mobile Device Security PolicyRequestSecurity · v1.0
- Human Resources Security PolicyRequestPeople · v1.3
- Incident Response PlanRequestOperations · v1.4
- Information Security PolicyRequestISMS · v3.2
- Network Security PolicyRequestSecurity · v1.3
- New Hire Onboarding PolicyRequestPeople · v1.1
- Risk Assessment & Management PolicyRequestISMS · v1.4
- Secure Software Development PolicyRequestSecurity · v1.4
- Security & Privacy Awareness PolicyRequestPeople · v1.2
- Vendor & Subprocessor Management PolicyRequestISMS · v1.2
- Vulnerability & Patch Management PolicyRequestSecurity · v1.1








































