percelX™

Trust Center

How we protect your data, who we share it with, and where we are on our compliance journey. Updated regularly — last reviewed July 25, 2026.

SOC 2 Type II
In progress
Audit fieldwork scheduled Q4 2026
HIPAA readiness
In progress
Technical safeguards live; BAAs finalizing
Encryption in transit
TLS 1.2+
Everywhere — API, dashboard, email links
Encryption at rest
AES-256
Field-level for PHI; volume-level for the DB
Scope of this page: PercelX products delivered from app.percelx.org, api.percelx.org, and related subdomains. Excludes the marketing site and social profiles.

Security

We build like a company that expects to be audited — because we do.

Field-level PHI encryption

Every field we classify as Protected Health Information is individually encrypted at rest using industry-standard authenticated encryption with managed key rotation.

TLS 1.2+ everywhere

All traffic between browsers, our API, and our subprocessors is encrypted in transit. HSTS enabled.

Least-privilege access

Role-based access control. Organization admins never see individual assessment answers — only aggregated cohort insight.

Full audit logging

Every admin action, data export, and access change is written to an immutable audit log.

Webhook signature verification

Inbound webhooks from payment and integration partners are cryptographically verified and processed idempotently to prevent replay.

Rate limiting & abuse controls

Per-IP and per-endpoint rate limits protect against brute-force and scraping.

Continuous dependency scanning

Automated advisory checks on every deploy; critical CVEs block production merges.

Isolated environments

Production data is fully isolated from non-production environments and never leaves controlled infrastructure.

Authentication

Application architecture

PercelX runs on managed services from a Tier-1 US cloud provider with redundancy across availability zones. Static assets are delivered from a global CDN, application logic runs on hardened compute with process-level supervision, and customer data is stored in an encrypted managed database with strict network isolation and IP allow-listing. AI reasoning is performed inside our cloud provider's boundary under existing data-protection agreements — customer content is never sent to third-party model providers outside that boundary.

Detailed architecture diagrams and a full subprocessor inventory are available to enterprise prospects under NDA — contact security@percelx.org.

Privacy

You own your data. We use it to serve you, not sell you.

Full details: Privacy Policy · Disclaimer.

Kids & families: the PercelX Kids product (ages 5–12) requires parental verification for account creation and stores child assessment data under stricter access controls. Parents may request data export or deletion at any time.

Subprocessors

Vendors that may process PercelX customer data on our behalf. We evaluate each for security posture and, where PHI is involved, require a Business Associate Agreement (BAA).

Vendor Purpose Data BAA Region
Tier-1 US cloud provider Application hosting, storage, content delivery, transactional email, and AI inference PHI Signed United States
Managed database provider Primary application data store PHI Signed United States
Payments processor Billing and subscription management No PHI (billing PII only) Not required United States
Marketing email provider Newsletter and event email — non-PHI only No PHI Scoped to non-PHI United States
Internal productivity suite Internal email and collaboration No customer PHI Enterprise agreement in place United States
Scheduling provider Consultation and demo scheduling Contact info only Not required United States
Source-control & CI provider Engineering source code and continuous integration No customer data Not required United States

Named vendors, versions, and regional deployment details are provided to enterprise prospects and customers under NDA as part of our Data Processing Addendum. Material changes to the underlying vendor list are communicated in advance to enterprise customers under contract. Request the full inventory or subscribe to change notifications at security@percelx.org.

Compliance

SOC 2 Type II

Audit fieldwork is scheduled for Q4 2026 through an AICPA-registered CPA firm using a leading GRC platform for continuous control evidence. On completion we will make the report available under NDA on request.

HIPAA

PercelX operates as a business associate for customers whose use of the platform involves Protected Health Information. Technical safeguards required by HIPAA §164.312 are live today — access control, audit controls, integrity controls, transmission security, and encryption at rest for PHI fields. BAAs with our infrastructure subprocessors are in place. A BAA between PercelX and the covered entity is provided as part of an enterprise agreement.

GDPR / privacy laws

Data-subject rights (access, correction, deletion, portability) are supported through our Privacy Policy contact.

Documents on request

Email security@percelx.org and we’ll respond within two business days.

Reporting a security concern

Please report suspected vulnerabilities or incidents directly to security@percelx.org. We commit to:

Please do not exfiltrate, modify, or expose customer data as part of a security test. Test against your own account or reach out to us to scope safe testing.

Contact

Different questions go to different mailboxes so we can route quickly.

Security

security@percelx.org

Privacy / data requests

privacy@percelx.org

Enterprise procurement

procurement@percelx.org

Support

support@percelx.org