2026
Our Security Commitment
SOC 2 Type II certification in progress — target: Q4 2026
At accelant, protecting your information and maintaining your trust is fundamental to how we operate.
TRUST & COMPLIANCE
ORGANIZATIONAL SECURITY
Information Security Program
We have a formal Information Security Program in place that is communicated throughout our organization. Our program follows the criteria set forth by the SOC 2 Framework — a widely recognized information security standard created by the American Institute of Certified Public Accountants (AICPA).
Third-Party Audits
accelant undergoes independent third-party assessments to test our security and compliance controls. This external validation ensures our program is operating as intended and meets industry expectations.
Roles and Responsibilities
Roles and responsibilities related to our Information Security Program are clearly defined and documented. All team members are required to review and acknowledge our security policies on an ongoing basis.
Security Awareness Training
Every accelant team member completes security awareness training covering industry best practices, including phishing recognition, password hygiene, and data handling. Training is updated regularly to reflect the current threat landscape.
Confidentiality Agreements
All team members are required to sign a confidentiality agreement before their first day of work. This commitment extends to any client information, credentials, and sensitive data encountered in the course of engagements.
Background Checks
We perform background checks on all new team members in accordance with applicable local laws, as part of our hiring and onboarding process.
ENDPOINT & TOOL SECURITY
Endpoint Protection
All company-issued devices are equipped with endpoint protection software, including antivirus and threat detection tools. We actively monitor for threats and maintain up-to-date security configurations across our fleet.
Password Management
All team members are required to use a company-approved password manager and adhere to password complexity requirements. This ensures credentials are strong, unique, and never reused across tools or client systems.
Multi-Factor Authentication
Where available, we enforce multi-factor authentication (MFA) across all business tools, platforms, and systems that hold sensitive information — including HubSpot portals and internal productivity tools.
Encryption in Transit
All data transmitted between accelant systems and external services is encrypted using TLS/SSL protocols, protecting information from interception during transfer.
ACCESS SECURITY
Least Privilege
AccessAccess to client systems, internal tools, and sensitive information is granted only to team members who require it to perform their specific role. We follow the principle of least privilege to minimize exposure and reduce risk.
Quarterly Access Reviews
We conduct quarterly reviews of team member access to sensitive systems and client environments. Access is revoked promptly when a team member changes roles or departs the organization.
Offboarding Controls
We maintain a formal offboarding process to ensure that access to all tools, client portals, and internal systems is revoked immediately when a team member exits the organization.
INCIDENT RESPONSE
Incident Response Plan
We maintain a documented incident response process for handling information security events. This includes defined escalation procedures, rapid mitigation steps, and a communication plan to keep affected parties informed in a timely manner.
VENDOR & RISK MANAGEMENT
Annual Risk Assessments
We conduct at least annual risk assessments to identify potential threats to our operations and client engagements, including considerations for fraud, data misuse, and operational disruption.
Vendor Risk Management
Before authorizing any new vendor or third-party tool, we conduct a risk assessment appropriate to the sensitivity of the data and access involved. We ensure that vendors we rely on maintain adequate security standards.
CONTACT US
If you have questions about our security practices or wish to report a potential security issue, please contact us at security@accelant.com.