Do you have SOC 2?
SOC 2 Type I/II is an active pathway with product controls and evidence collection. We do not display a fake certification seal. Contact sales for the evidence pack under NDA.
Route5
Procurement
Copy-paste answers for InfoSec reviews. Machine-readable ledger at /api/r5e/assurance.
Do you have SOC 2?
SOC 2 Type I/II is an active pathway with product controls and evidence collection. We do not display a fake certification seal. Contact sales for the evidence pack under NDA.
Do you have ISO 27001?
ISO 27001 / 27701 are pathways with an ISMS control map in the evidence vault. Not certified until an auditor letter exists.
Is data encrypted at rest and in transit?
Yes. Integration secrets use AES-256-GCM at rest. TLS in transit with HSTS in production.
Do you support SSO / SAML / SCIM?
SSO via Clerk (Google/OIDC). SAML via Clerk Configure on Enterprise. SCIM 2.0 Users API is live.
Do you support MFA?
Yes — enforceable through Clerk organization policies for Enterprise workspaces.
Do you process cardholder data?
No. Payments go through Stripe. Route5 is out of PCI CHD scope.
How do data subject requests work?
Authenticated users submit DSR via /api/r5e/privacy/dsr. SLA target 30 days. Legal hold may delay erasure.
What is your retention / deletion policy?
Workspace admins set retention months in Settings → Security. Legal hold blocks erasure. Account deletion is a queued workflow with status — not just “email us”.
Is customer data used to train models?
No. Route5 does not train models on customer workspace data. Inference vendors are listed as subprocessors. Enterprise AI opt-out is available.
Where is data hosted?
Primary hosted SaaS is US (Vercel + Supabase project region). EU residency / multi-region enforcement is a sales pathway for regulated deals.
Do you have a vulnerability disclosure process?
Yes — /security/vdp and /.well-known/security.txt. Acknowledge target: 2 business days.
What are RTO / RPO?
Published targets: RTO 24h / RPO 4h for hosted SaaS. Refine in MSA for enterprise deals.
Do you provide a VPAT?
Living VPAT draft at /security/vpat. Formal third-party WCAG audit is process-only until scheduled.
Can we export our data?
Yes. Commitments, audit CSV/JSON, and trust export with checksums. No lock-in.