Skip to content

Security & Trust

A security posture built to the bar enterprise and public-sector buyers enforce.

Where-I is independently audited, federally authorized, and deployed in 47 countries. This page is the procurement artifact your security team will read first — written for the reviewer, not the buyer.

  • AttestedSOC 2 Type II
  • AuthorizedFedRAMP Moderate
  • Deployed in47 countries
Monochrome duotone map excerpt rendered as a technical figure
Figure 1 — Where-I tile infrastructure, U.S. east-coast region.

Certifications & attestations

  • SOC 2 Type II

    Annual, independent audit covering Security, Availability, and Confidentiality.

  • FedRAMP Moderate

    Authorized for U.S. federal agencies handling controlled unclassified information.

  • ISO 27001

    Certified Information Security Management System, renewed annually.

  • GDPR · CCPA · HIPAA-aligned

    Aligned controls and data-processing addenda available for EU, U.S., and healthcare workloads.

Operational security architecture

Four pillars of the Where-I security program.

The controls below map cleanly to SOC 2 Trust Services Criteria, NIST 800-53 (Moderate baseline), and ISO 27001 Annex A. Each is owned by a named control owner and reviewed quarterly.

01

Data protection

Customer data is encrypted at rest using AES-256 and in transit using TLS 1.3 with modern cipher suites. Field-level encryption is available for named PII fields. Keys are managed in a FIPS 140-2 Level 3 HSM-backed KMS, with customer-managed key (CMK) options on AWS, GCP, and Azure.

  • AES-256 at rest, TLS 1.3 in transit
  • FIPS 140-2 Level 3 HSM-backed KMS
  • Optional customer-managed keys (BYOK)
  • Field-level encryption for named PII

02

Access control

Role-based access control (RBAC) with SAML 2.0 single sign-on, SCIM 2.0 provisioning, and mandatory MFA for all human access. Privileged actions require just-in-time elevation with an immutable approval trail. Service-to-service traffic uses short-lived workload identities, never long-lived secrets.

  • SAML 2.0 SSO + SCIM 2.0 provisioning
  • Mandatory MFA on every human account
  • JIT elevation for privileged actions
  • No long-lived service credentials in production

03

Infrastructure

The Where-I tile and query stack runs on SOC 2 and FedRAMP-authorized cloud regions, segmented by tenant with network policies enforced at the cluster boundary. Petabyte-scale tile infrastructure is hardened to CIS Level 1 baselines, with immutable base images and a private container registry.

  • Tenant segmentation at the cluster boundary
  • CIS Level 1 hardened base images
  • Private container registry, signed images
  • Sub-200ms query response with regional failover

04

Audit & monitoring

Every API call, admin action, and data export produces a tamper-evident audit record retained for the life of the customer relationship. Logs are streamed to a segregated SIEM with integrity hashing. Continuous control monitoring surfaces drift against our baseline within minutes, not weeks.

  • Tamper-evident audit log with integrity hashes
  • SIEM-streamed, segregated from production
  • Continuous control monitoring (CCM)
  • Customer-visible audit log access on request

For your security team

Questions your CISO will ask, answered plainly.

The answers below are written for the person filling out the questionnaire, not the person who forwarded the link. If something is missing, write to [email protected] and a human will respond within one business day.

How often is Where-I penetration tested, and by whom?
Independent penetration testing is conducted at least annually by a CREST-accredited firm, with a separate web application and infrastructure scope. A summary letter is available under NDA; full red-team reports are released to qualified prospects in procurement.
What is your encryption posture at rest and in transit?
AES-256 at rest, TLS 1.3 in transit, FIPS 140-2 Level 3 HSM-backed key management. Customer-managed keys (BYOK) are available on AWS KMS, GCP Cloud KMS, and Azure Key Vault for Enterprise tier.
How will we be notified of a security incident?
Confirmed incidents are communicated to the customer's designated security contact within 72 hours of triage, in line with GDPR Article 33 obligations. Notifications include scope, affected systems, mitigation steps, and a post-incident report once containment is complete.
Can we review your sub-processors and access audit logs?
Yes. The current sub-processor list is published at where-i.net/legal/sub-processors with 30 days' notice of any change. Customers on Enterprise and Public-Sector tiers can stream audit logs into their own SIEM and retain them for the duration of the contract.

Data residency

In-region processing, with explicit guarantees.

Customer data is processed and stored in the region selected at contract signature. Cross-region replication is opt-in, encrypted, and logged.

  • United Statesus-east-1, us-west-2
  • European Unioneu-central-1, eu-west-1
  • United Kingdomuk-south-1
  • Asia-Pacificap-southeast-1, ap-northeast-1

Standard contractual clauses and EU-U.S. Data Privacy Framework participation are documented in the DPA.

Procurement documentation

Paperwork your procurement team will ask for.

The documents below are signed, dated, and ready to drop into your vendor review packet. Counter-signature on a redlined MSA is typically returned within five business days.

  • Master Services AgreementStandard MSA, negotiable on Enterprise tier
  • Data Processing AddendumGDPR-aligned, includes SCCs module 2
  • Business Associate AgreementAvailable for HIPAA-aligned workloads
  • Security QuestionnaireCAIQ v4 & SIG Lite pre-completed
  • Penetration Test SummaryReleased under NDA

Send your procurement contact to [email protected] to request any item.

Next step

Talk to a Where-I engineer about your environment.

A 30-minute working session with someone who has answered your exact control question before. Bring your questionnaire — we will fill in the boxes live.