Compliance & Standards
Who is this for: Partners, enterprise customers, and compliance or security officers evaluating MomentScience's data protection and regulatory posture.
Outcome: Understand MomentScience's SOC 2 Type II compliance, GDPR and CCPA alignment, and the security controls in place to protect customer data and platform availability.
Overview
MomentScience is committed to protecting customer data and maintaining the highest standards of security, privacy, and reliability. Our fully managed platform is designed to help you engage customers confidently, knowing that data and workflows are safeguarded by industry best practices.
We are proud to be SOC 2 compliant, a milestone that demonstrates our rigorous approach to data protection, operational reliability, and customer trust. SOC 2 compliance validates that we secure sensitive information, maintain platform availability, and safeguard confidentiality through independently audited controls.
From a technical perspective, SOC 2 compliance means that our systems and processes have been independently assessed against the AICPA Trust Services Criteria for:
- Security: Protection against unauthorized access
- Availability: Reliable access to the platform when you need it
- Confidentiality: Safeguarding sensitive data throughout its lifecycle
This certification reinforces our ongoing commitment to continuous improvement in security and compliance.
Compliances
MomentScience meets recognized industry standards:
- SOC 2 (Type II): Independently audited against the AICPA Trust Services Criteria for security, availability, and confidentiality.
- Privacy Compliance: Adheres to GDPR and CCPA principles, including data minimization, user consent, and transparent data handling.
For the latest compliance details, visit our Trust Center.๏ปฟ
Controls
We implement multiple layers of controls across product, data, network, application, endpoint, and corporate domains. These controls are continuously monitored and tested to ensure effectiveness.
Examples of Controls
- Product Security
- Situational awareness for incidents
- Data Security
- Testing for reliability and integrity
- Network Security
- Transmission confidentiality
- Monitoring anomalous behavior
- Centralized collection of security event logs
- Application Security
- Conspicuous link to privacy notice
- Formal approval of changes
- Endpoint Security
- Malicious code protection (anti-malware)
- Device or container-based encryption
- Endpoint encryption
- Corporate Security
- Code of Business Conduct
- Defined organizational structure
- Clear roles and responsibilities
A full list of controls is available in the Trust Center.๏ปฟ
Resources
Supporting documentation and policies provide transparency and guidance for compliance practices:
- Policies (33), including:
- Code of Business Conduct
- Compliance Policy
- Encryption Policy
- Documents (1)
- Code of Business Conduct Policy
Additional resources can be accessed in the Trust Center.
For compliance-related inquiries, please contact [email protected].