Last updated: July 2026
At Activegence, security is foundational to everything we build and operate. We implement enterprise-grade security controls to protect our infrastructure, our clients' data, and the integrity of every system under our management.
SOC 2 Compliance. Activegence maintains SOC 2 Type II compliance, demonstrating that our security controls meet the highest standards for data protection. Our controls are independently audited annually against the AICPA Trust Services Criteria, covering security, availability, processing integrity, confidentiality, and privacy. We provide audit reports to clients and prospects upon request under NDA.
Encryption. All data is encrypted both in transit and at rest. We use TLS 1.3 for all data transmitted over public networks and AES-256 encryption for data stored at rest. Database backups, file storage, and internal communications are encrypted using industry-standard algorithms. Encryption keys are managed through dedicated key management services with regular rotation schedules.
Access Controls. We enforce strict access controls following the principle of least privilege. All team members have role-based access to systems based on job function. Multi-factor authentication (MFA) is required for all internal systems and administrative access. Privileged access is logged, monitored, and subject to regular review. Access is revoked immediately upon role change or termination.
Incident Response. Activegence maintains a comprehensive incident response plan with clearly defined roles, escalation procedures, and communication protocols. Our security team conducts regular tabletop exercises and simulations to ensure readiness. In the event of a security incident affecting client data, we commit to notifying affected parties within 72 hours in accordance with applicable regulations and contractual obligations.
Penetration Testing. We conduct regular penetration testing of our infrastructure and applications using independent third-party security firms. Tests cover external-facing systems, internal networks, and application layers. Critical and high-severity findings are remediated within defined SLAs. We also maintain a bug bounty program to encourage responsible disclosure from the security research community.
Infrastructure Security. Our infrastructure is hosted on enterprise cloud providers with SOC 2, ISO 27001, and FedRAMP certifications. We implement network segmentation, web application firewalls, DDoS protection, and real-time monitoring with automated alerting. All production systems are configured using infrastructure-as-code with security policies enforced through automated compliance checks.