Trust Center
Information Security Overview
This page summarizes, at a high level, how we protect data across our platform. It's intentionally a summary — not a technical architecture document — consistent with standard practice for public-facing security disclosures.
| Area | Summary |
|---|---|
| Encryption in transit | TLS 1.2 or higher enforced on all connections to our platform. |
| Encryption at rest | AES-256, applied by default across our cloud infrastructure. |
| Access control | Role-based access control (RBAC) governs staff access to client data and systems, scoped to what each role actually needs. |
| Hosting | Microsoft Azure, hosted in the United States. |
| Backups | Automated daily backups with a 7-day retention window. |
| Vulnerability management | As a growing firm, we're formalizing a documented vulnerability-scanning and patch-management cadence. Ask us directly about our current approach. |
Business Continuity
Our platform runs on automated daily backups with a 7-day retention window. As we grow, we're formalizing a documented disaster-recovery plan with defined recovery time and recovery point objectives (RTO/RPO). Ask us directly for our current approach.
A full Information Security Policy is available to clients and prospective clients under NDA — email info@dpoboard.com, or use our document request form.