ClonePartner

Security & Compliance

Security and compliance at ClonePartner

Certifications and security program overview.

Controls
118
Certifications
05
Subprocessors
13

01

Updates

01 update

  1. SOC 2 Type II observation period underway

    ClonePartner has entered the observation period for its fourth consecutive SOC 2 Type II audit, conducted by our independent auditor, Prescient Security. The audit evaluates the operating effectiveness of our security controls across the observation window, with the renewed report available to customers under NDA on completion.

02

Certifications

05 active

  • SOC 2 Type II

    ● Active

    Feb 1, 2026 → Jan 31, 2027

  • ISO 27001

    ● Active

    Jul 1, 2024 → Jun 30, 2027

  • GDPR

    ● Active

    Active

  • HIPAA

    ● Active

    Active

  • CASA Type II

    ● Active

    Active

05

Controls

118 controls

  • Single Sign-On (SSO)Enterprise SSO via SAML and OIDC so teams authenticate through their own identity provider.
  • Two-Factor Authentication (2FA)Multi-factor authentication enforced for privileged and administrative access.
  • Role-Based Access Control (RBAC)Least-privilege, role-based permissions across the platform.
  • AES-256 Encryption at RestAll data at rest is encrypted with AES-256.
  • Latest TLS in TransitAll data in transit is encrypted with the latest TLS (1.2+).
  • Data SovereigntyChoose the region where your data is stored and processed so it stays within your required jurisdiction.
ClonePartner runs a data-minimizing, engineer-led model: customer data is processed only for the duration of a migration or engagement and is deleted within a commercially reasonable period once the work completes. That discipline keeps our footprint small and keeps you in control of where your data lives. Our security program is independently audited — SOC 2 Type II and ISO 27001 — and continuously monitored through Sprinto, with each control mapped to a live evidence check rather than a point-in-time screenshot. Access follows least-privilege RBAC with enforced MFA, all data is encrypted in transit (TLS 1.2+) and at rest (AES-256), and infrastructure runs on SOC 2-certified providers across US and EU regions. We run annual third-party penetration tests, maintain a documented incident-response plan with customer notification within 48 hours, and give at least 15 days' notice before adding or replacing any subprocessor.

08

Subprocessors

13 vendors

  • Purpose
    Foundation-model provider reached via Cursor, under the same no-training, limited-retention terms
    Location
    United States
  • Purpose
    Scheduling and calendar management for support sessions
    Location
    United States
  • Purpose
    Content delivery, DNS, and edge security
    Location
    Global edge network (HQ: United States)
  • Purpose
    AI-assisted engineering tooling — privacy mode enforced, no model training, zero- or limited-retention
    Location
    United States
  • Purpose
    Hosting, infrastructure and database services
    Location
    Customers' Designated Region
  • Purpose
    Foundation-model provider reached via Cursor, under the same no-training, limited-retention terms
    Location
    United States
  • Purpose
    Business email, documents, and internal collaboration
    Location
    United States / EU
  • Purpose
    Cloud infrastructure and compute services
    Location
    Customers' Designated Region
  • Purpose
    Foundation-model provider reached via Cursor, under the same no-training, limited-retention terms
    Location
    United States
  • Purpose
    Transactional email delivery
    Location
    United States
  • Purpose
    Team and customer-channel communications
    Location
    United States
  • Purpose
    Form and survey capture for intake and feedback
    Location
    Belgium (EU)
  • Purpose
    Unified API framework powering internal orchestration
    Location
    United States

09

FAQ

06 questions

  • 01Is our data safe during a migration?

    Yes. Migrations are engineer-led with data encrypted in transit (TLS 1.2+) and at rest (AES-256), least-privilege access for our engineers, and field-level validation on every record — backed by our zero-downtime, zero-data-loss approach.

  • 02Does ClonePartner keep our data after the project ends?

    No. Once a migration or engagement completes, Customer Data is deleted within a commercially reasonable period in line with our retention policy. Certified deletion is available on written request.

  • 03Which compliance standards does ClonePartner meet?

    ClonePartner maintains SOC 2 Type II and ISO 27001, and complies with HIPAA and GDPR. Detailed documentation, including our ISO certificate and SOC 2 report, is available under NDA via legal@clonepartner.com.

  • 04Can we sign a DPA before migrating?

    Absolutely. Our Data Processing Agreement — including the EU and UK Standard Contractual Clauses — is published at clonepartner.com/dpa, and a signed copy is available on request to legal@clonepartner.com.

  • 05Who are your subprocessors?

    We use DigitalOcean and OVHcloud for infrastructure, Cal.com and Tally.so for scheduling and intake, and Truto for integration orchestration. All are listed in Schedule C of our DPA and in the Subprocessors section above.

  • 06What happens if there is a data breach?

    We notify affected customers without undue delay and, where feasible, within 48 hours of becoming aware of a breach, and cooperate fully on investigation, mitigation, and any regulatory notifications.

10

Documents

05 available

  • GDPR Compliance CertificateRequest
  • HIPAA Compliance CertificateRequest
  • ISO 27001 CertificateRequest
  • Penetration Test SummaryRequest
  • SOC 2 Type II ReportRequest

11

Policies

23 documents

The information-security policies behind our program. Documents are shared on request — submit a request and we’ll send a secure link once approved.

  • Acceptable Use PolicyRequest
    ISMS · v2.0
  • Access Control PolicyRequest
    ISMS · v2.1
  • Application Security PolicyRequest
    Security · v1.1
  • Asset Management PolicyRequest
    ISMS · v1.3
  • Business Continuity & Disaster Recovery PlanRequest
    Operations · v1.3
  • Change Management PolicyRequest
    Operations · v1.3
  • Code of Business ConductRequest
    People · v1.4
  • Cryptography & Key Management PolicyRequest
    Security · v1.2
  • Data Backup PolicyRequest
    Operations · v1.3
  • Data Classification & Handling PolicyRequest
    Privacy · v1.2
  • Data Protection & Privacy PolicyRequest
    Privacy · v2.0
  • Data Retention & Disposal PolicyRequest
    Privacy · v1.1
  • Endpoint & Mobile Device Security PolicyRequest
    Security · v1.0
  • Human Resources Security PolicyRequest
    People · v1.3
  • Incident Response PlanRequest
    Operations · v1.4
  • Information Security PolicyRequest
    ISMS · v3.2
  • Network Security PolicyRequest
    Security · v1.3
  • New Hire Onboarding PolicyRequest
    People · v1.1
  • Risk Assessment & Management PolicyRequest
    ISMS · v1.4
  • Secure Software Development PolicyRequest
    Security · v1.4
  • Security & Privacy Awareness PolicyRequest
    People · v1.2
  • Vendor & Subprocessor Management PolicyRequest
    ISMS · v1.2
  • Vulnerability & Patch Management PolicyRequest
    Security · v1.1