PTTCRM / Trust / Security

Security pack

Answers procurement and IT typically ask before a PTTCRM demo. Nothing here claims a certificate that has not been issued.

Encryption and access

Transport uses TLS 1.2+. Staff access to demo inbox and CMS is least-privilege and audited. The marketing site does not embed the operations console.

Data residency

Production CRM and portal data is hosted in Singapore (AWS ap-southeast-1) unless a contract says otherwise. Marketing-site demo leads are stored in the same region.

DPA and SCCs

EU/UK prospects use the Data Processing Agreement on this site. Standard Contractual Clauses apply where a sub-processor transfers data outside the EEA, as stated on each vendor DPA (AWS, Stripe).

Sub-processors

The public list is limited to vendors actually in use. Names prefixed for internal drafting are never shown.

SOC 2

SOC 2 Type I is in progress. The Trust Center links a report only after PO and auditor sign-off. We do not display a badge before that.

SSO and MFA

Enterprise SSO (Keycloak OIDC) and MFA for selected roles are implemented on the staff path — availability depends on deployment configuration. See the Enterprise IT questionnaire for SIG Lite answers and live posture.

Availability

Target is 99.9% monthly uptime for the marketing site, demo API, and public CMS read path. The status page publishes incidents and a 90-day history only after production monitoring has enough measured days.

← Back to Trust Center · Data Processing Agreement · Enterprise IT questionnaire