Trust Center

Where Layer8 Systems stands on security, data handling, and compliance — and who we share data with to run the Service.

Last updated July 2026

Compliance status

SOC 2 Type II: not yet started

We have not engaged an auditor and make no claim to be SOC 2 compliant or “in progress” today. We’ve been building toward audit readiness — the controls below are real and operating, not aspirational — and will start a formal Type II engagement once a customer requirement or funding milestone calls for one. If SOC 2 is a requirement for your organization, tell us at security@layer8systems.ca — this is exactly the kind of signal that moves the timeline up.

Security posture

  • Application-layer encryption at rest for notes, device configs, and credentials.
  • Optional end-to-end (zero-knowledge) vaults in CryptKeepr for the most sensitive secrets.
  • Tamper-evident, append-only security audit trail with daily hash-chained anchors.
  • Per-request authorization checks — no ambient trust between users or organizations.
  • TLS 1.3 in transit, HSTS preload, and a restrictive Content-Security-Policy.
  • Dependency and secret scanning on every change, before it reaches production.

Full technical security details →

Status

Live uptime and incident history for the web application, backend, and the third-party platforms we depend on.

View status page →

Subprocessors

Third parties that process personal data on our behalf to deliver the Service. We give at least 14 days’ notice before adding or materially changing one — see our Privacy Policy §4.

SubprocessorPurposeLocation
ClerkAuthentication and session managementUnited States
ConvexApplication database and backend computeUnited States
VercelApplication hosting and content deliveryUnited States (global edge network)
PolarBilling and subscription managementUnited States
ResendTransactional email deliveryUnited States
SentryApplication error monitoringUnited States
Vercel Analytics & Speed InsightsProduct usage and performance analyticsUnited States

Full data-sharing details for each subprocessor are in the Privacy Policy.

Legal & documentation

Security questionnaires & vendor reviews

Filling out a security questionnaire for your procurement process? Email security@layer8systems.ca and we’ll send our pre-filled CAIQ-Lite responses.