1. Compliance & reports
- SOC 2 Type II audited annually with report available under NDA.
- GDPR-ready processing with DPA available upon request.
- Security controls cover encryption, access governance, and monitoring.
Security, compliance, and data handling details for procurement and risk teams.
This page outlines compliance posture, data residency, retention defaults, sub-processors, and how to request reports.
SOC 2 Type II
Annual audit with report available under NDA.
HIPAA / BAA
BAAs available for healthcare customers.
Data residency
US, Canada, and EU regions supported.
Reach Central offers HIPAA-ready deployments and signs Business Associate Agreements (BAAs) for covered entities and healthcare partners.
A detailed, current list of named sub-processors is available upon request.
Customer data can be hosted in US, Canada, or EU regions depending on contract requirements.
A Data Processing Addendum (DPA) is available for GDPR and enterprise privacy requirements. Reach Central also supports custom contractual security addendums when required.