Our Security Commitments
Last Updated: August 12, 2026
Security is not a feature we added. It is the reason Root Evidence exists. Here is what we commit to for every customer.
Protecting Your Data
Customer data is encrypted in transit and at rest using strong, industry-standard cryptography. Access to production systems follows least privilege, requires multi-factor authentication, and is limited to personnel who need it to do their jobs. We do not sell customer data, and we are transparent about the vendors that help us deliver the service.
Building Securely
Security is built into how we ship. Code changes are reviewed and tested before release, our pipelines run static analysis and dependency scanning, and we hold our own infrastructure to the same scrutiny we bring to yours. Findings get fixed, not filed away.
Our People
Every team member passes a background check before joining and completes security awareness training during onboarding and annually after that. Our policies are documented, acknowledged by the whole team, and reviewed on a regular cadence.
Staying Available
The platform runs on redundant cloud infrastructure with continuous monitoring and a documented disaster recovery plan. When something changes that affects you, we communicate it.
When Something Goes Wrong
We maintain a documented incident response process. If an incident affects your data, we will notify you promptly and keep you informed through resolution. Security researchers can reach us at security@rootevidence.com, as published in our security.txt.
Independent Validation
Our security program is undergoing an independent SOC 2 Type II examination. And we are the first vulnerability management platform to back our findings financially, because commitments mean more when there is money behind them.
Questions
Questions about our security practices? Contact us at security@rootevidence.com.
See your risk in dollars.
Book a demo and see the vulnerabilities that actually cost money.