SOC 2 Type II
Annual audit covering how we run the workspace that holds your pages, tests, and translations. Report available under NDA.
Request the reportSecurity
Pages, experiments, and translations live in one workspace. This page documents how that workspace is secured.
Compliance and assurance
Certifications, testing, and audit trails tied to publishing landing pages - not generic SaaS claims. If a badge is still in progress, we say so.
Annual audit covering how we run the workspace that holds your pages, tests, and translations. Report available under NDA.
Request the reportStandard contractual clauses, an EU hosting option, and a published subprocessor list for market teams that need them.
Information security management certification underway. We share status honestly rather than implying a badge we do not hold yet.
When a landing page goes live, a translation is approved, or a role changes, the event is recorded and retained for review.
Limit an agency or country team to the brands and domains they own - not every property in the workspace.
Third-party tests run annually and before major releases. Summaries available to enterprise buyers on request.
Access and identity
CRO agencies, local marketers, and translators often share one LiftLander account. SSO and per-site roles keep that workable without oversharing.
Connect Okta, Entra ID, Google Workspace, or JumpCloud so marketers sign in the same way as the rest of your stack.
Provision and deprovision editors and reviewers from your IdP when people join or leave a growth team.
Require identity-provider login for the workspace and turn off password access for stricter environments.
Set idle and absolute timeouts. Role changes force re-authentication before publish rights apply.
Owner, Admin, Editor, Reviewer, and Analyst - mapped to publish, translation approval, and billing visibility.
Security and ops can reconstruct who gained publish or approval rights, and when.
Data handling
Encryption, residency, analytics defaults, and deletion windows you can paste into a vendor questionnaire.
TLS 1.3 with HSTS on product and customer page domains. AES-256 for databases, object storage, and backups.
Choose EU (Frankfurt) or US (Virginia) when the workspace is created. APAC available on request. Data does not roam for support.
After workspace deletion, primary data is removed within 24 hours and encrypted backups within 35 days.
Conversion metrics use filtered traffic. Aggregated by default; raw IPs are not kept beyond invalid-traffic filtering.
Cloud KMS with scheduled rotation. Key material is not exportable to LiftLander operators.
Hosting, CDN, AI translation inference, billing, and email - listed below with 30-day notice before changes.
See the listSubprocessors
Infrastructure and AI partners that may process workspace or page data. Workspace owners get 30 days' notice before this list changes. A signed DPA is available on request.
Email security@liftlander.com for the DPA. Related: Privacy policy.
Request the security package or book a walkthrough with the team that ships the product.