Skip to content
SECURITY · TRUST CENTER Last audit: Q3 2025 · Reports current

Enterprise security, audited.

Genkatsu processes 2.7B sales interactions per quarter for 2,400+ revenue teams across 38 countries. The platform holds three active enterprise certifications, runs on infrastructure trusted by three of the Fortune 100, and ships with a 99.98% uptime guarantee. Everything below is the evidence behind those numbers — written for security engineers, CISOs, and procurement evaluators who don't accept vendor hand-waves.

SOC 2 Type II ISO 27001 HIPAA Forrester Wave Leader · 2024 G2 #1 · Conversation Intelligence 99.98% platform uptime
system.status all systems operational uptime.30d 99.983%
audit.soc2 renewed 2025-Q3 audit.iso27001 renewed 2025-Q1
audit.hipaa attested 2025-Q2 data.regions US-East · US-West · EU · APAC
sub-200ms nudge fired · coaching latency 174ms · queue depth 0
01 / CERTIFICATIONS

Three certifications. Three independent auditors. Renewed on a public cadence.

Each report covers the controls a procurement checklist actually asks about: access management, change control, encryption, vendor risk, incident response, and business continuity. Request the full reports under NDA at the bottom of this page.

CERT 01 ACTIVE

SOC 2 Type II

AICPA Trust Services Criteria

Auditor
Coalfire Federal LLC
Report date
2025-Q3 (Sep 18, 2025)
Coverage period
12 months continuous
Trust criteria
Security · Availability · Confidentiality
Scope
Genkatsu production platform, San Francisco + Bengaluru

No exceptions noted in the most recent report.

CERT 02 ACTIVE

ISO 27001

Information Security Management System

Auditor
BSI Group America, Inc.
Certificate issued
2025-Q1 (Feb 04, 2025)
Valid through
2028-Q1 · annual surveillance
Statement of Applicability
Annex A, 93 controls · 0 non-conformities
Scope
Design, build, and operation of the Genkatsu AI coaching platform

Renewed surveillance audit scheduled 2026-Q1.

CERT 03 ACTIVE

HIPAA

Health Insurance Portability and Accountability Act

Attestor
Schellman & Co., LLC
Attestation date
2025-Q2 (May 22, 2025)
Framework
HIPAA Security Rule · 45 CFR §164.308–§164.312
BAAs available
On request, counter-signed within 48 hours
Scope
Customer tenants transmitting PHI through Genkatsu

Not certified for GDPR — by design. See data residency below for EU controls.

What we deliberately do not claim: no GDPR certification · no PCI-DSS scope · no consumer-app compatibility · no mobile-call recording
02 / DATA HANDLING

How Genkatsu protects data in motion and at rest.

The control map below is the same one our security team walks enterprise auditors through. We hold ourselves to the standards a CISO would write if they were building the platform — because several of our engineers came from environments where that was their day job.

Encryption

  • In transit. TLS 1.3 on every public endpoint. mTLS on all internal service-to-service traffic. Certificate rotation automated through AWS ACM with a 30-day maximum validity.
  • At rest. AES-256-GCM on all customer data stores. Per-tenant data keys wrapped by a customer-scoped KMS key (AWS KMS, FIPS 140-3 validated modules).
  • Bring your own key. Available on the Enterprise tier via AWS KMS external key store — Genkatsu never sees the plaintext key material.

Tenant isolation

  • Logical isolation at the database layer with row-level security keyed on tenant_id; physical isolation available for Enterprise + tier via dedicated cluster.
  • All cross-tenant queries blocked at the query planner. Tenant boundary fuzzing is part of every release's security test suite.
  • Background jobs cannot access more than one tenant's data per worker invocation. Workers are torn down after every job.

Retention & deletion

  • Default retention: 24 months for transcripts, 36 months for derived coaching signals. Configurable per tenant down to 30 days.
  • Hard delete propagation: a tenant-initiated purge completes across all derived stores within 72 hours, verified by an automated integrity job.
  • Backups retained for 35 days, then cryptographically shredded. Backup deletion is logged and signed.

Access control

  • Least-privilege RBAC with mandatory SSO via SAML 2.0 or OIDC; SCIM 2.0 provisioning included.
  • All production access is via short-lived, just-in-time credentials. Standing access to production is prohibited.
  • Privileged actions recorded to an append-only audit log shipped to Datadog and the customer's optional SIEM forwarder.
03 / DATA RESIDENCY

Four regions. Pick the one your data-sovereignty policy already names.

Every Genkatsu tenant is pinned to a primary processing region at provisioning. Data never leaves that region except for explicit, audited cross-region replication you can turn off. Latency numbers below are p50 measured from a sample of 2,400+ production tenants over the last 30 days.

Dark world map showing four regional processing zones for Genkatsu data residency: US-East, US-West, EU-Frankfurt, and APAC-Sydney.
Live tenant distribution as of 2025-Q4 · 2,400+ tenants across 38 countries
  • US-EAST-1 DEFAULT

    Northern Virginia

    AWS us-east-1 · Ashburn, VA

    p50 ingest latency
    38ms
    p50 coaching nudge
    174ms
    Tenants served
    1,140
  • US-WEST-2 OPT-IN

    Oregon

    AWS us-west-2 · Boardman, OR

    p50 ingest latency
    41ms
    p50 coaching nudge
    182ms
    Tenants served
    410
  • EU-FRA-1 EU DEFAULT

    Frankfurt

    AWS eu-central-1 · Frankfurt, DE

    p50 ingest latency
    52ms
    p50 coaching nudge
    198ms
    Tenants served
    640
  • APAC-SYD-1 OPT-IN

    Sydney

    AWS ap-southeast-2 · Sydney, AU

    p50 ingest latency
    61ms
    p50 coaching nudge
    211ms
    Tenants served
    210

Region pinning is enforced at the application and network layers. Cross-region replication requires an explicit tenant setting and is logged. Customers in regulated industries (financial services, healthcare, EU public sector) typically pin to a single region with replication disabled.

04 / SUBPROCESSORS

Every vendor that touches customer data — disclosed plainly.

This is the standard DPA subprocessor schedule. Each vendor is listed with the function it performs, the data scope it receives, and its own security posture. We notify customers at least 30 days before adding a new subprocessor, and the change log is append-only.

  1. 01

    Amazon Web Services

    Primary cloud infrastructure · compute, storage, KMS, networking across all four regions.

    Data scope
    All customer data at rest and in transit
    Certifications
    SOC 2 Type II · ISO 27001 · ISO 27017 · ISO 27018 · HIPAA-eligible services
    Region pinning
    Matches tenant's selected processing region
  2. 02

    Cloudflare

    Edge proxy, WAF, DDoS protection, and TLS termination at the public perimeter.

    Data scope
    Encrypted request/response metadata · no payload storage
    Certifications
    SOC 2 Type II · ISO 27001 · PCI DSS 4.0
    Region pinning
    Global anycast · logs pinned to tenant region
  3. 03

    OpenAI Enterprise

    Foundation model provider for coaching generation, summarization, and pattern extraction.

    Data scope
    Transcript excerpts routed through OpenAI Enterprise · zero retention & zero training enabled
    Certifications
    SOC 2 Type II · ISO 27001 · HIPAA BAA available
    Region pinning
    US-only inference endpoint · EU customers may opt out
  4. 04

    Datadog

    Application performance monitoring, log aggregation, and the audit-log forwarder.

    Data scope
    Application logs · infrastructure metrics · sanitized audit events
    Certifications
    SOC 2 Type II · ISO 27001 · HIPAA BAA available
    Region pinning
    US1 / EU1 regional clusters · pinned per tenant
  5. 05

    Snowflake

    Analytics warehouse for aggregated, anonymized coaching-performance metrics.

    Data scope
    Anonymized rollups only · no raw transcripts, no PII
    Certifications
    SOC 2 Type II · ISO 27001 · HIPAA · FedRAMP Moderate
    Region pinning
    AWS region matching tenant's primary processing zone
  6. 06

    Auth0 by Okta

    Identity, SSO, and SCIM provisioning for Genkatsu end users.

    Data scope
    User email, name, role · no call or deal data
    Certifications
    SOC 2 Type II · ISO 27001 · HIPAA BAA available
    Region pinning
    US / EU regional tenants · tenant-selected

Full DPA and subprocessor change notification workflow available on request. Customers may object to a new subprocessor within 30 days of notification; unresolved objections allow contract termination without penalty.

05 / REQUEST REPORTS

Pull the actual SOC 2 and ISO 27001 reports. Under NDA.

If you're a qualified evaluator — security engineer, CISO, procurement lead, GRC analyst — we hand over the full SOC 2 Type II report, the ISO 27001 certificate and statement of applicability, the HIPAA attestation letter, and the latest penetration-test executive summary within one business day.

  1. 01

    Sign the mutual NDA

    One-way or mutual — your call. We counter-sign within 24 hours via DocuSign.

  2. 02

    Receive the document pack

    SOC 2, ISO 27001, HIPAA attestation, and pen-test summary delivered to your verified work email.

  3. 03

    Bring questions to a live session

    A sales engineer who can actually read the report walks you through the architecture diagram and answers what the documents don't.

Not ready to sign an NDA? Book a demo with a sales engineer who has read every line of the SOC 2 report and can answer live.

Security & compliance inbox
[email protected]
Direct line
+1 (415) 555-0182
Headquarters
548 Market Street, Suite 42100, San Francisco, CA 94104