Skip to content

GoRefer Trust Center

Trust Center

Updated September 2026

Unknown

Status unavailable

No recent status update

Your data — and your clients' data — deserves a clear explanation of how it's protected. This Trust Center documents GoRefer's security practices, privacy policies, and compliance commitments in plain language so you can make informed decisions.

See the security controls built into GoRefer, our published policies and our current compliance status in one place. For documents about our hosting providers, staff practices or independent assessments, make a request through the Trust Portal.

AES-256

Field encryption

20+

Security controls documented

72 hr

Notification policy target

Scoped

Audit records

Security & Compliance Posture

IRS 4557 control support
AES-256 field encryption
HTTPS transport
MFA Available
AWS services
SOC 2 · Status in progress
GDPR rights & policies
HIPAA Scope Review
99.9% uptime target

Control Domain Scorecard

Encryption

AES-256-GCM field protection; TLS connections

Access Control

RBAC, MFA, least privilege, session mgmt

Network Security

Security headers and rate limiting; edge protection details on request

Data Protection

PII field encryption, data minimization

Incident Response

P0–P3 response targets and notification policy

Business Continuity

RPO < 1hr · RTO < 4hr · Quarterly DR test target

AI Governance

No training on customer data, audit logged

Compliance

GDPR / IRS support · SOC 2 Type II status: in progress; not yet attested.

Penetration Testing

Security review and assessment requests



Our Core Data Commitments

We will never sell your data or your clients' data — to anyone, for any reason.

Authorized export workflows cover supported firm records. Contact us to confirm scope and access.

GoRefer policy prohibits using customer inputs to train models; provider terms govern external processing.

Our notification policy targets 72 hours, subject to applicable duties and incident assessment.


Private Documents

Request access to NDA-protected documents: pentest reports, full DPA, architecture diagrams.

Request Access →

Report a Vulnerability

Found a security issue? Disclose it responsibly via our security contact form.

View Disclosure Policy →

Security Questions

Enterprise procurement, security questionnaires, or general inquiries.

security@gorefer.io →