Security
Security & Trust at Civenza.
Civenza is built for public-sector accountability, and we hold our own operations to the same standard. Below is our current security and compliance posture, stated plainly.
SOC 2 Type II
Controls operating and evidenced since 2026; independent audit scheduled with enterprise onboarding.
PCI DSS
All payments processed by Stripe (PCI DSS Level 1). Card data never touches Civenza systems.
GDPR
Privacy-by-design practices: no selling of data, no ad tech, rights honored on request.
WCAG 2.1 AA
Accessibility-first design; formal third-party assessment planned.
Encryption
TLS in transit, AES-256 at rest.
Access control
Role-based, least-privilege, MFA-protected administration, database-enforced tenant isolation.
Backups & recovery
Daily automated backups with quarterly tested restores.
How we operate.
Civenza runs a 16-policy internal security program covering everything from access management to secure development. We conduct quarterly access reviews with evidence capture, so controls are not just written down but demonstrably operating. Risk assessments and vendor reviews happen annually. Our incident response plan includes customer notification commitments, so if something affects you, you hear it from us first.
Our subprocessors.
We maintain a current list of the vendors that process customer data on our behalf: subprocessor list.
Documentation & reporting.
Full security documentation, policies, and audit artifacts are available to customers and qualified prospects under NDA: legal@civenza.io. Report a security concern: security@civenza.io.