Security you can verify.
MachineCert is built on the same security posture that LogMeOnce has maintained for over ten years. SOC 2 Type II, ISO 27001, HIPAA shared responsibility, GDPR-ready.
Posture you can audit.
SOC 2 Type II
Independent attestation of security, availability, and confidentiality controls. Renewed annually.
ISO 27001
Information security management aligned with ISO/IEC 27001. Certified annually.
HIPAA shared responsibility
Clear documentation of MachineCert's and customer's respective responsibilities under HIPAA.
GDPR-ready
DPA, subprocessors register, and data residency controls. EU customer data stays in the EU.
Least-privilege access
Read-only API access by default. Customer data is never used to train models or shared with third parties.
Penetration testing
Annual third-party penetration testing. Findings disclosed to customers under NDA.
MachineCert leverages infrastructure providers that maintain independently audited security controls (see Infrastructure). MachineCert does not claim to independently hold SOC 2 or ISO 27001 certification unless and until separately audited. We’re transparent about what is inherited from our providers versus operated by MachineCert.
Responsible disclosure, real response.
Security researchers can report vulnerabilities through our coordinated disclosure program. Acknowledged within one business day. Resolved fast.