# Security and Compliance

*Category: security*
*Topics: security, compliance, encryption, gdpr, soc2*

Acme prioritizes security and compliance, ensuring the protection of user data through various measures. This page is for users and organizations seeking information on Acme's security and compliance standards. Acme's security measures include encryption, secure storage of secrets, and regular testing. The company also provides features for enterprise customers to enhance security.

## Key points

- SOC 2 Type II certified
- GDPR compliant
- Data encrypted in transit and at rest
- Secrets stored in an isolated vault
- Annual third-party penetration testing

## Content

## Security & Compliance
Acme is SOC 2 Type II certified and GDPR compliant. All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Secrets used in workflows are stored in an isolated vault and never logged. Enterprise customers can enable SAML single sign-on, scoped API tokens, and IP allowlisting. We undergo annual third-party penetration testing and publish a status page at status.example.com.

## Source

- Canonical URL: https://example.com/security
- Typed record: https://agent-visibility.yddhh.top/index.json
