Skip to content

GoRefer Trust Center

Trust Center Changelog

Updated September 26, 2026

These entries record changes to our published documentation. Older entries describe it as it stood at the time; they are not a statement about today's controls, audits or dates. See the current Trust Center pages for what applies now, and ask us for current records if you need them.

This changelog tracks material updates to GoRefer's security practices, privacy policies, and compliance documentation. Subscribe to updates by emailing privacy@gorefer.io.

Version History

v2.4

September 26, 2026

Updated access, monitoring and operations statements to match how GoRefer works today

UPDATED

Clarified that Security Hub is a platform-operations tool and distinguished web token lifetimes from the extension session cap.

UPDATED

Scoped field encryption, AI context and cookie descriptions to the relevant workflows.

UPDATED

Replaced cloud, network, staff-training, backup and incident-history statements we could not verify with our policy targets and details of what you can request.

v2.3

September 25, 2026

Clarified implemented controls, operational targets and provider data flows

UPDATED

Corrected scoped decrypted-intake access, key migration, account-retention and Gio case-cleanup descriptions.

UPDATED

Disclosed marketing-site Meta Pixel and raw document-recognition processing separately from case-context redaction.

UPDATED

Removed statements we could not support — that all controls were verified, that independent testing had taken place, and about HIPAA — and separated policy targets from completed assessments.

v2.2

June 1, 2026

Earlier control-mapping and audit-logging documentation update; not independent SOC 2 attestation

UPDATED

Compliance page — SOC 2 Trust Service Criteria status updated from 'In Scope' to 'Implemented' with detailed control descriptions for all 9 categories

UPDATED

Compliance roadmap — SOC 2 Type II milestone updated to reflect all controls implemented, audit engagement in progress

UPDATED

Data export audit-logging documentation updated; coverage and tamper-evidence depend on the export workflow

ADDED

Documented enhancement areas include password policy configuration, vulnerability scanning and session timeout enforcement; ask us for their current status

v2.1

April 4, 2026

Major Trust Center expansion — 4 new pages, hub redesign, and compliance timeline

ADDED

AI Security & Governance page (/trust/ai-security) — data handling, controls, prompt injection protection

ADDED

Business Continuity & DR page (/trust/business-continuity) — RPO/RTO targets, backup strategy, DR testing program

ADDED

Employee & Operational Security page (/trust/employee-security) — staff controls, training program, offboarding procedures

ADDED

Network Security page (/trust/network-security) — WAF, DDoS mitigation, rate limits, HTTP security headers

UPDATED

Trust Hub — posture scorecard with 9 domains, key stats, grouped navigation, core data commitments

UPDATED

Security page — HTTP security headers table and clean security incident history section

UPDATED

Infrastructure page — anonymized vendor names, improved backup & DR detail with cross-links

UPDATED

Compliance page — visual compliance roadmap timeline (GDPR → IRS 4557 → CCPA → SOC 2 Q3 2026 → ISO 27001 2027)

UPDATED

Subprocessors page — grouped by category, data sensitivity levels (High/Medium/Low), summary stats

UPDATED

Subprocessors — added a data-sensitivity level to all 9 vendor entries

v2.0

April 1, 2026

Full Trust Center launch — expanded from a single security page to a structured multi-page system

ADDED

Full Trust Center at /trust/* with 15 structured pages

ADDED

Dedicated Security, Privacy, Compliance, Infrastructure, and Access Control pages

ADDED

Subprocessors page with vendor table (8 vendors listed)

ADDED

Data Protection and Data Retention pages with structured tables

ADDED

Incident Response page with P0–P3 severity levels and SLAs

ADDED

Vulnerability Disclosure policy with responsible disclosure commitments

ADDED

Data Processing Addendum (DPA) summary page

ADDED

Penetration Testing policy page

ADDED

Private Document Portal (request access for NDA-gated documents)

ADDED

Security contact form (direct disclosure to security@gorefer.io)

ADDED

Sidebar navigation with grouped sections and active-page highlighting

UPDATED

The old /security page now redirects to /trust/security

v1.1

June 15, 2025

Added Security Hub details and field-level encryption documentation

ADDED

Security Hub section with firm health score details

ADDED

Field-level encryption list (SSN, EIN, bank accounts, driver's license)

UPDATED

Infrastructure section updated to reflect MongoDB Atlas migration

UPDATED

Added AI service providers to subprocessors list

v1.0

January 25, 2025

Initial security and compliance page published

ADDED

Initial security & compliance page at /security

ADDED

Six security pillars: Encryption, Tenant Isolation, RBAC, Auth, Monitoring, Infrastructure

ADDED

Privacy Policy (v1.0)

ADDED

Terms of Service (v1.0)

ADDED

Cookie Policy