Trust Center

Enlyft Trust Commitment

We are committed to ensuring the security, confidentiality, and integrity of your data. As a trusted partner to our customers, we have processes in place to protect your data from unauthorized access and to ensure it is used appropriately to serve your needs.

SOC 2 Type 2 Microsoft Azure GDPR ISO 27001 TLS in transit
Data security

Your data, isolated by design.

The Enlyft Platform Architecture is built from the ground up so that each customer’s data is managed separately from other customers and from our proprietary Enlyft Company Graph.

  • Data received from each customer is placed in separate, isolated data stores.
  • Customer data is used only for models built for use by that customer.
  • All production modeling runs on our cloud-hosted platform within a virtual private cloud.
  • Transport Layer Security protects data in transit between our data center and our customers.
Enlyft data architecture: isolated customer data stores
How we protect your data

Security built into every layer.

AICPA SOC 2 compliance

We are a certified SOC 2 Type 2 compliant organization. SOC 2 is a standard established by the American Institute of Certified Public Accountants (AICPA), a framework followed by SaaS companies to safeguard the privacy and security of customer data. It is a voluntary compliance standard that assesses the procedures and control processes in an organization.

More about SOC for Service Organizations →

Data center security

The Enlyft platform is hosted on Microsoft Azure. Azure meets a broad set of international and industry-specific compliance standards, including GDPR, ISO 27001, HIPAA, FedRAMP, and SOC 1 and SOC 2, plus country-specific standards. Rigorous third-party audits verify Azure’s adherence to the strict security controls these standards mandate.

Network security

  • All data is secured within a private network in our data center.
  • Subnets are used to isolate the various application servers.
  • Third-party tests detect vulnerabilities and apply patches preemptively.

Backup and recovery

  • All mission-critical systems and data stores, including customer data, are backed up regularly to ensure quick recovery from failure.
  • To ensure security, the backups are held within our cloud provider’s data center.

Security monitoring and assessments

  • Enlyft partners with external vendors to conduct penetration testing and evaluate overall security.
  • Enlyft continually monitors potential security risks and applies the latest security patches across our software stack.

Data purge and retention

Customer data is used only for models built for that customer, and is purged 90 days after termination of a business contract unless otherwise specified in the contract or instructed by the client.

FAQ

Security and privacy, answered.

Is Enlyft SOC 2 compliant?

Yes. Enlyft is a certified SOC 2 Type 2 compliant organization. SOC 2 is a framework established by the AICPA that assesses the controls a SaaS company uses to safeguard the privacy and security of customer data.

Where is Enlyft’s platform hosted?

The Enlyft platform is hosted on Microsoft Azure, which meets a broad set of international and industry-specific standards, including GDPR, ISO 27001, HIPAA, FedRAMP, and SOC 1 and SOC 2. Azure’s adherence to these controls is verified by rigorous third-party audits.

How is my data kept separate from other customers?

Data from each customer is placed in separate, isolated data stores and is used only for models built for that customer. All production modeling runs within a virtual private cloud, and your data is kept separate from other customers and from our proprietary Enlyft Company Graph.

Is my data encrypted in transit?

Yes. Enlyft uses Transport Layer Security (TLS) to protect data in transit between our data center and our customers.

Does Enlyft comply with GDPR and CCPA?

Yes. Enlyft is built to support GDPR and CCPA requirements, and our Azure hosting environment meets GDPR and a range of other international compliance standards.

What happens to my data if we end our contract?

Customer data is purged 90 days after termination of a business contract, unless otherwise specified in the contract or instructed by the client.

How does Enlyft test and monitor its security?

Enlyft partners with external vendors to conduct penetration testing and evaluate overall security, continually monitors for potential risks, and applies the latest security patches across our software stack. Mission-critical systems and customer data are backed up regularly within our cloud provider’s data center for quick recovery.

How do I request your SOC 2 report or other security documentation?

All of Enlyft's current security and compliance documentation — including our SOC 2 Type 2 report — is available through our Trust Portal. Visit trust.enlyft.com to review our security posture and request documents directly. For any other privacy, data protection, or security questions, contact our team.

FAQ

Trust Center, answered.

Is Enlyft SOC 2 compliant?

Yes. Enlyft is a certified SOC 2 Type 2 compliant organization. SOC 2 is a framework established by the AICPA that assesses the controls a SaaS company uses to safeguard the privacy and security of customer data.

Where is Enlyft’s platform hosted?

The Enlyft platform is hosted on Microsoft Azure, which meets a broad set of international and industry-specific standards, including GDPR, ISO 27001, HIPAA, FedRAMP, and SOC 1 and SOC 2. Azure’s adherence to these controls is verified by rigorous third-party audits.

How is my data kept separate from other customers?

Data from each customer is placed in separate, isolated data stores and is used only for models built for that customer. All production modeling runs within a virtual private cloud, and your data is kept separate from other customers and from our proprietary Enlyft Company Graph.

Is my data encrypted in transit?

Yes. Enlyft uses Transport Layer Security (TLS) to protect data in transit between our data center and our customers.

Does Enlyft comply with GDPR and CCPA?

Yes. Enlyft is built to support GDPR and CCPA requirements, and our Azure hosting environment meets GDPR and a range of other international compliance standards.

What happens to my data if we end our contract?

Customer data is purged 90 days after termination of a business contract, unless otherwise specified in the contract or instructed by the client.

How does Enlyft test and monitor its security?

Enlyft partners with external vendors to conduct penetration testing and evaluate overall security, continually monitors for potential risks, and applies the latest security patches across our software stack. Mission-critical systems and customer data are backed up regularly within our cloud provider’s data center for quick recovery.

How do I request your SOC 2 report or other security documentation?

All of Enlyft's current security and compliance documentation — including our SOC 2 Type 2 report — is available through our Trust Portal at trust.enlyft.com, where you can review our security posture and request documents directly. For any other privacy, data protection, or security questions, contact our team at enlyft.com/contact.

Have a security question we didn’t cover?

Request our SOC 2 report, security documentation, or talk to our team directly.

Contact our team Email [email protected]