Tekmetric

Tekmetric Trust Center

Tekmetric ensures robust data security through continuous SOC 2 Type II audits, ISO/IEC 27001 certification, strict data access controls based on least privilege, comprehensive encryption of customer data both at rest and in transit using TLS 1.2+, and secure payment processing via Stripe’s PCI DSS–validated hosted payment fields.

Security at Tekmetric

You can trust Tekmetric to keep your data safe.

SOC 2 Type II Certified

Tekmetric holds SOC 2 Type II certification, meaning the design and operating effectiveness of security controls are continuously audited. This continuous verification underscores Tekmetric's dedication to secure data management and commitment to protecting your organization’s data and meeting comprehensive compliance needs.

ISO/IEC 27001 Certified

Tekmetric is officially certified for ISO/IEC 27001, demonstrating that its Information Security Management System (ISMS) is aligned with international security best practices. Robust processes and procedures to handle information assets demonstrate the company’s commitment to the highest level of internal compliance and security.

Data Security

Tekmetric retains only the data necessary to provide you and your customers with an exceptional experience. Access is limited to only those with a legitimate business need and is granted based on the principle of least privilege.

All customer data, in addition to S3 buckets, is encrypted at rest. Sensitive collections and tables also use row-level encryption, meaning the data is encrypted even before it hits the database so that neither physical access nor logical access to the database is enough to read the most sensitive information.

Tekmetric uses TLS 1.2 or higher everywhere data is transmitted over potentially insecure networks. Features such as HSTS (HTTP Strict Transport Security) are used to maximize the security of data in transit. Server TLS keys and certificates are managed by AWS and deployed via Application Load Balancers.

Payment Card Industry Data Security Standards (PCI DSS)

Tekmetric partners with Stripe to provide a hosted payment field for handling all payment card data. The cardholder enters all sensitive payment information in a payment field that originates directly from Stripe’s PCI DSS–validated servers.

Encrypted, In Transit and At Rest

All customer data, in addition to S3 buckets, is encrypted at rest. Sensitive collections and tables also use row-level encryption. This means the data is encrypted even before it hits the database so that neither physical access nor logical access to the database is enough to read the most sensitive information.

Tekmetric uses TLS 1.2 or higher everywhere data is transmitted over potentially insecure networks. Features such as HSTS (HTTP Strict Transport Security) are used to maximize the security of data in transit. Server TLS keys and certificates are managed by AWS and deployed via Application Load Balancers.

We Take Security Seriously

Tekmetric knows an educated team is key to keeping your data safe.

Security Training

Tekmetric provides continuous comprehensive security training to all employees.

Endpoint Protection

All corporate devices are centrally managed and are equipped with mobile device management software and anti-malware protection.

Continuous Improvement

Tekmetric's controls are iterative, continuously maturing to improve effectiveness, increase auditability, and decrease friction.

Secure Development Process

Tekmetric implements a secure Software Development process to ensure the platform meets customer expectations during production and beyond. The platform is regularly penetration tested to verify the security of your data as well.