Skip to main content

Security

Security & Trust at Civenza.

Civenza is built for public-sector accountability, and we hold our own operations to the same standard. Below is our current security and compliance posture, stated plainly.

In progress

SOC 2 Type II

Controls operating and evidenced since 2026; independent audit scheduled with enterprise onboarding.

Via Stripe

PCI DSS

All payments processed by Stripe (PCI DSS Level 1). Card data never touches Civenza systems.

Aligned

GDPR

Privacy-by-design practices: no selling of data, no ad tech, rights honored on request.

In progress

WCAG 2.1 AA

Accessibility-first design; formal third-party assessment planned.

Active

Encryption

TLS in transit, AES-256 at rest.

Active

Access control

Role-based, least-privilege, MFA-protected administration, database-enforced tenant isolation.

Active

Backups & recovery

Daily automated backups with quarterly tested restores.

How we operate.

Civenza runs a 16-policy internal security program covering everything from access management to secure development. We conduct quarterly access reviews with evidence capture, so controls are not just written down but demonstrably operating. Risk assessments and vendor reviews happen annually. Our incident response plan includes customer notification commitments, so if something affects you, you hear it from us first.

Our subprocessors.

We maintain a current list of the vendors that process customer data on our behalf: subprocessor list.

Documentation & reporting.

Full security documentation, policies, and audit artifacts are available to customers and qualified prospects under NDA: legal@civenza.io. Report a security concern: security@civenza.io.