# Trust & Security

## Deep integration, governed by enterprise-grade security

Locus runs alongside enterprise systems including ERP, OMS, WMS, TMS, and FMS, and ingests live operational signals from traffic to telematics. The platform is designed around customer-controlled data, dedicated tenancy, and independently audited security.

**Platform availability:** 99.97% uptime

## Certified to international security and privacy standards

Independent auditors verify Locus’s controls, giving enterprise security and procurement teams the evidence they need for review and approval.

### ISO 27001:2022

Locus is certified for ISO 27001:2022, demonstrating a robust Information Security Management System. Certificates are available upon request.

### ISO 27701:2019

Locus is ISO 27701:2019 certified, demonstrating its capability to protect customers’ personal information through a Privacy Information Management System.

### HIPAA Compliant

Locus is compliant with the Health Insurance Portability and Accountability Act (HIPAA), reflecting its commitment to safeguarding protected health information (PHI) and upholding the privacy rights of patients, clients, and partners.

Its data handling practices are supported by administrative, technical, and physical safeguards designed to ensure the confidentiality, integrity, and availability of PHI.

### GDPR Compliant

Locus is compliant with the General Data Protection Regulation (GDPR), reflecting its commitment to protecting personal data and upholding the privacy rights of clients, users, and partners.

Its data processing practices have been independently validated through a GDPR gap assessment conducted by DNV. Locus’s Data Processing Agreement is available on request via `privacy@locus.sh`.

### SOC 2 Type II

Locus is SOC 2 Type II compliant, providing assurance that the organization has implemented and maintains effective controls to protect customer data.

### SOC 3 Report

Locus has obtained a SOC 3 report, providing public assurance that the organization maintains effective controls for security, availability, and confidentiality. The report reflects Locus’s commitment to transparency and industry-standard practices for protecting customer data.

## Secured by design, end to end

Locus uses layered controls to protect customer data across encryption, access, threat detection, recovery, development practices, and privacy management.

## Customer data protection

### Encryption

- AES 256-bit encryption protects data at rest.
- TLS 1.2 and HTTPS secure data in transit, reducing the risk of interception and unauthorized access.

### Availability

- High-availability deployments with geographically redundant backups support operational continuity and data security.
- Application-layer auto-scaling helps handle both malicious attacks and sudden surges in legitimate traffic.

### Access control

- SAML and ADFS-based Single Sign-On support secure authentication.
- Role-Based Access Control provides granular permissions aligned to organizational roles.
- Customizable password policies support compliance with global security standards.
- Corporate network access is restricted through Zero Trust Network Access or VPN solutions.
- Comprehensive audit trails provide traceability for user activity and support regulatory compliance.

### Threat protection

- Next-generation antivirus protects devices and servers against evolving cyber threats.
- Multi-layered defenses include a Web Application Firewall, Intrusion Detection System, and DoS protection.

### Business continuity

- Business continuity and disaster recovery protocols are in place to support uninterrupted operations during disruptions, with regular testing and updates.

### Cyber liability insurance

- Cyber liability insurance covers security and privacy breaches, forensic investigations, social engineering attacks, and ransomware.

## Secure development lifecycle

### Product planning

- Security and privacy requirements are integrated into the design phase to support compliance and risk mitigation throughout the product lifecycle.

### Development and code review

- Developers are trained on secure coding and code review practices, including OWASP Top 10 vulnerabilities and prevention techniques.
- Automated code scanning is used to identify security issues.

### Change management

- Change management is integrated into SDLC processes across internal and external stakeholders.
- Customers are informed in advance of major breaking changes.

### Segregation of duties

- Production system access is restricted by job role and granted on a need-to-know basis for limited periods.
- Access is periodically reviewed.

### Testing

- Applications undergo periodic security testing aligned to OWASP standards.
- Internal and external vulnerability assessments and penetration testing are conducted regularly.
- Locus does not currently operate a public bug bounty program, but it recognizes responsible security research through its Responsible Vulnerability Disclosure Policy.

## Privacy by design and by default

### Privacy Information Management System

- Locus is ISO 27701:2019 certified and maintains an established, implemented, monitored, and audited Privacy Information Management System.
- The system tracks the collection, storage, processing, access, transfer, retention, and removal of personal information.

### Retention of personal information

- Retention periods for personal information are configurable.
- Locus maintains a dedicated process and channel for deletion of personal data upon request.

### Sub-processors

- Locus identifies, assesses, and empanels sub-processors to ensure appropriate fit.

### Privacy rights

Certain privacy laws provide individuals with the right to request access to or deletion of personal information held by an organization. Data subject rights requests related to personal information processed by Locus can be submitted via `dpo@locus.sh`."