Keeping your account and your data secure is essential to our mission. This page summarises how Magnity protects customer data and where you can verify it. The full control set, our policies and the SOC 2 report are available through the Magnity Trust Center.
Yes. Magnity is SOC 2 Type I, monitored continuously by Vanta. Customer data is hosted in the EU, encrypted in transit and at rest, and access to encryption keys is restricted to authorised systems. Every statement on this page corresponds to a control or policy published on the Trust Center, where you can also request our system description and network diagram.
Never. Your data is yours. We do not sell it, and we do not share it beyond what is needed to run the service, as described in our privacy policy. Internally, access is limited to a need-to-know basis under our access control policy, and customer data is deleted when a customer leaves.
All communication between your browser and Magnity is encrypted with HTTPS (TLS), so the integrity and privacy of your data are protected while you work with us. Data is encrypted at rest as well, and access to encryption keys is restricted to authorised systems, in line with our cryptography policy.
Customer data is hosted in the EU. Business continuity and disaster recovery plans are established and tested, and cybersecurity insurance is maintained.
User access and permissions are managed centrally by your administrators, with unique account authentication enforced on every account. Single sign-on is available, so your team can sign in through your own identity provider. On our side, production systems require unique authentication, employee background checks are performed, and access to customer environments is governed by our access control policy.
Penetration testing is performed, control self-assessments are conducted, and an incident response plan is in place. Vanta monitors the control set continuously, and the Trust Center shows when it was last updated.
Data retention procedures and a data classification policy are established, and customer data is deleted when a customer leaves. How we handle personal data is set out in our privacy policy.
The Magnity Trust Center lists the full control set across infrastructure security, organisational security, product security, internal security procedures and data and privacy. From there you can request the SOC 2 report, the system description, the network diagram and our policies: access control, asset management, business continuity and disaster recovery, code of conduct, cryptography, data management, human resource security and incident response.
Explore the Magnity Trust Center →We are here to help. Reach out to privacy@magnity.ai if you would like to know more about our infrastructure, compliance roadmap or technical setup, or start a security review through the Trust Center.