All customer data is stored in AWS (us-west-2), encrypted in transit (TLS 1.2+) and at rest (AES-256). Access is tightly controlled using Role-Based Access Control, multi-factor authentication (MFA), and least privilege principles. Each client operates in a custom instance with full tenant isolation, and backend systems follow strict security and audit procedures.
WingRep is SOC 2 Type II and ISO 27001 compliant. Security documentation, audit reports, and internal policies are available through our Trust Vault.

Our SOC 2 Type II report covers a full audit window of operating effectiveness across security, availability, and confidentiality. Independently audited and continuously monitored, with the report available to prospective and existing customers under NDA.

Our ISO 27001 certification demonstrates a comprehensive information security management system. We identify, assess, and treat security risks across people, processes, and technology, with controls verified by an accredited third-party auditor.
Our security team is happy to walk your team through our controls.
contact@wingrep.ai