Security and compliance, built in
Enterprise-grade controls, clear policies, and a trust program built for teams that take data protection seriously.
Data protection
We design controls to protect customer data across storage, transmission, access, and operations. For review evidence and documentation, the Trust Center is the source of truth.
Security artifacts, policies, questionnaires, and reports are managed through the Trust Center and provided via access request.
Open Trust CenterEncrypted connections for traffic, secure storage practices, and controlled key handling.
Strong authentication and scoped permissions to reduce risk and limit exposure.
Logging and monitoring to detect issues early and support accountability.
Clear runbooks and escalation procedures for security events and operational incidents.
How we secure EmailBison
Security is enforced through layered controls across infrastructure, application, and operations.
Secure development
Change control, reviews, and vulnerability management practices.
Incident response
Runbooks and escalation procedures to respond fast and communicate clearly.
Vendor risk
Vendor oversight and infrastructure review practices used in our trust program.
Doing a vendor review?
Request access in the Trust Center to review questionnaires, policies, and supporting artifacts.
Frequently Asked Questions (FAQ)
Where can I see your compliance status and documentation?
Visit our Trust Center at trust.emailbison.com to view status and request access to documentation. We require an NDA before giving access.
Are you GDPR compliant?
Yes. EmailBison is GDPR compliant and certified by a third party. You can view our compliance policies, DPA, and certification report in our trust centre.
Are you HIPAA compliant?
Yes. EmailBison is HIPAA compliant and certified by a third party. You can view our compliance policies and certification report in our trust centre.
Are you SOC2 Type II certified?
Yes. EmailBison has an active SOC2 Type II certification. You can view our certification report and policies in our trust centre.
Do you conduct regular penetration tests?
Yes. EmailBison conducts regular penetration tests (using a third party). We also use continuous vulnerability scanning during all deployment events.
Will you complete security questionnaires?
Yes, if you're in an active enterprise sales cycle, we are happy to complete security questionnaires.
Can I choose geographical locations for my data?
For enterprise customers, we are flexible with deployments across North America and Europe. You can choose to house your data in any of our data centre locations.
Security review, made easy
Request documentation for procurement, compliance, and vendor assessments.