Security & compliance
The data never leaves unredacted.
Most vendors scrub sensitive fields after they arrive. Northwind redacts in the collector, inside your network, so the control is demonstrable at the config rather than argued from policy.
Practices
What we actually do.
Encryption everywhere
TLS 1.3 in transit, AES-256 at rest, and per-tenant keys with optional customer-managed keys on Business.
Redaction at the source
The collector redacts before data leaves your network, so sensitive fields never cross the boundary rather than being scrubbed after arrival.
Least privilege by default
New members get read-only access. Every escalation is time-boxed and written to an audit log that cannot be edited from the product.
Tested by people who are not us
Annual third-party penetration test, continuous automated scanning, and a public bug bounty with no scope carve-outs for the ingest path.
Compliance
Certifications and attestations.
Reports and questionnaires are available under NDA without going through sales.
-
SOC 2 Type II
Audited annually by a Big Four firm. Report on request.
-
ISO 27001
Certified since 2023, covering all production systems.
-
HIPAA
BAA available on Business and Enterprise plans.
-
GDPR
EU data residency, DPA and SCCs available.
-
HITRUST
Inheritable controls documented for customer audits.
-
PCI DSS
Level 1 service provider for in-scope deployments.
Disclosure
How we behave when it goes wrong.
A security page that only lists certifications is telling you what an auditor checked, not what happens on a bad day.
| Initial notification | Within 24 hours of confirmation |
|---|---|
| Affected-customer detail | Within 72 hours |
| Public post-mortem | Within 14 days, including root cause |
| Bug bounty scope | All production systems, no ingest carve-out |
| Uptime SLA | 99.95% on Business, credited automatically |
| Status page | Independent of our own infrastructure |
Send us your security questionnaire.
We answer it before the first call rather than after the third.