Wiss Trust Center | Data Security Overview

Customer Trust Portal

Wiss Trust Center

A clear overview of our data security posture for customers, partners, and prospects.

We understand that our customers entrust us with sensitive information and expect the highest standards of security, confidentiality, and reliability.

Program overview

How We Protect Your Data

Overview

A practical approach to information security.

Our information security program is designed to align with industry best practices and recognized standards, including SOC 2 Type II requirements, and is continuously enhanced through independent assessments, risk management activities, and ongoing monitoring.

Our systems leverage industry-leading cloud and security technologies to provide a secure and resilient environment for customer information.

Security program

Designed for resilience and continual improvement.

Infrastructure security

Our infrastructure is designed with resiliency, redundancy, and business continuity considerations to support system availability and operational resilience.

External assessments & testing

Independent third-party assessments, periodic penetration tests, and external vulnerability scanning activities are conducted to evaluate and continuously improve our security posture.

Security governance

Our security program is overseen through a dedicated vCISO engagement provided by an external company, supporting governance, risk management, compliance oversight, and continuous improvement initiatives.

Protection & access

Protecting information and governing access.

Data encryption

Customer information is protected through encryption controls both in transit and at rest. Endpoint data is encrypted using full-disk encryption, and Microsoft 365 security capabilities support identity protection and data security.

Access control

Access is granted based on least privilege and need-to-know principles. Multi-factor authentication, periodic access reviews, and timely access revocation processes are implemented.

Monitoring & awareness

Monitoring, response, and awareness.

Security monitoring & threat detection

Security technologies, including endpoint protection, email security, web security, and managed detection and response solutions, support continuous monitoring, threat detection, and incident response capabilities.

Security awareness & training

Personnel receive information security awareness training during onboarding and periodically thereafter, including phishing simulations and policy acknowledgements.

Resilience & risk

Resilience extends beyond a single system.

Third-party risk management

Critical service providers undergo security assessments and periodic reviews.

Business continuity & data recovery

Documented incident response, backup, recovery, and business continuity processes support operational resilience.

Security at a glance

Security at a Glance

A quick-reference list of our primary security and compliance posture baselines:

  • SOC 2 Type II Attested
  • Dedicated vCISO Program
  • Independent Third-Party Penetration Testing
  • Continuous External Vulnerability Scanning
  • 24/7 Continuous Security Monitoring & Threat Detection
  • Annual & Milestone Security Awareness Training
  • Fully Documented Incident Response Program
  • Robust Business Continuity & Disaster Recovery (BCDR) Plans
  • Rigorous Third-Party Vendor Risk Management
  • End-to-End Encryption in Transit (TLS 1.2+) and At Rest (AES-256)

Security documentation

Prepare a documentation request

Select the resource you need and provide the information required for a secure review workflow.

If a Wiss team member is assisting with this request, enter their name.

Your request will be sent to Wiss for review. Access to restricted documentation may require a separate review and NDA. Privacy Policy