turgo is SOC 2 Type II attested (annual) and ISO 27001 certified (2025), with AES-256 encryption at rest and TLS 1.3 in transit always on. Security documentation, the sub-processor list, and reports are available at turgo.ai/legal and via your security portal.
Attestations and certifications
SOC 2 Type II covering security, availability, and confidentiality, audited annually by an independent firm. ISO 27001 certified as of 2025. GDPR Article 28 compliant, CCPA compliant, and HIPAA-eligible with a BAA available on Enterprise. The current reports are shared under NDA on request.
How your data is protected
Encryption at rest with AES-256 (managed keys via KMS; bring-your-own-key on Enterprise) and in transit with TLS 1.3 minimum for all API and database connections. Data is stored multi-AZ with continuous backups. Access is least-privilege and every access is logged.
Operational security
SSO and SCIM for identity (see Set up SSO and SCIM provisioning), scoped API keys stored hashed (see Authentication and API keys), and a full audit trail of user and system actions. Internal access to customer data is role-gated, logged, and reviewed. Vulnerability management and penetration testing run on a regular cadence.
Getting security documents
Prospects and customers can request the SOC 2 report, ISO certificate, pen-test summary, and completed security questionnaires from your account team or security@turgo.ai. The DPA and sub-processor list are public at turgo.ai/legal.