Your Security Is Our Priority
At Whatfix, protecting the confidentiality, integrity, and availability of customer data is central to the design and operation of our DAP services. Security and privacy are embedded throughout the SaaS lifecycle, from development through ongoing operations.
Our program is supported by industry-recognized frameworks, strong technical and organizational controls, and continuous monitoring to safeguard data against unauthorized access, disclosure, alteration, and loss. We operate under a shared responsibility model and support our customers in meeting applicable regulatory and data protection requirements.
This Trust Center provides transparency into our security, privacy, and compliance practices, including relevant policies, certifications, and documentation.
**Note: All documents, materials, and information accessed through this Trust Center are Confidential and subject to the terms of your Non-Disclosure Agreement (NDA) with Whatfix. By accessing this content, you agree to handle all information responsibly and not disclose it to unauthorized parties.*
Founded in 2014
Here are the controls implemented at Whatfix to ensure compliance, as a part of our security program.
Role Based Access Controls
Audit Logging
Data Security
Service Level Agreement
Single Sign On
Access Monitoring
Backups Enabled
Encryption at Rest
Encryption in Transit
Physical Security
Data Loss Prevention
Firewall
IDS/IPS
Wireless Security
Cloud Access Security Broker (CASB)
Conspicuous Link To Privacy Notice
Vulnerability Disclosure Program
Code Analysis
Software Development Life Cycle
Credential Management
Vulnerability & Patch Management
Web Application Firewall
Code of Business Conduct
Roles & Responsibilities
Competency Screening
Personnel Screening
Security & Privacy Awareness
Performance Review
Automated Reporting
Incident Reporting Assistance
Risk Framing
Risk Assessment
Fraud
Third-Party Criticality Assessments
Assigned Cybersecurity & Privacy Responsibilities
Subservice organization evaluation
Subprocessor Requirements
Data Protection Impact Assessment (DPIA)
Data Protection Officer (DPO)
Chief Privacy Officer (CPO)
Incident Handling
Privacy Act Statements
Asset Ownership Assignment
Validate Security Controls
Review of Third-Party Services
Inventory of Endpoint Assets
Email Protection
Employee Training
Incident Response
Internal Assessments
Single Sign On