NorthernPlus is built so that staying compliant is the path of least resistance. We built to the legal industry's compliance bar first, one of the most demanding there is, and that posture now protects every company we serve. Below is a straight snapshot of where we are today.
We do not oversell what we have. Each item below carries its real status.
| Item | Where it stands | Status |
|---|---|---|
| SOC 2 Type II | Audit window underway. We can share our current control framework, monitoring posture, and progress under NDA during a procurement review. | Pending |
| HIPAA-aligned posture | Encryption, access controls, audit logging, and data segregation align with HIPAA Security Rule requirements. BAA execution available on the Advanced tier; full BAA-eligible posture across all subprocessors is on the roadmap. | Today |
| Encryption in transit | TLS 1.3 across every surface: client intake, admin console, voice agent, and integrations. No exceptions. | Today |
| Encryption at rest | AES-256 at rest across application database, file storage, and backups. Field-level encryption for sensitive intake data is on the roadmap. | Today |
| Right to be forgotten | Two-click client redaction for GDPR and CCPA requests. PII is scrubbed in place; engagement audit trails are preserved per your industry's recordkeeping requirements. | Today |
| Penetration testing | Independent third-party penetration test scheduled. Report available to enterprise customers under NDA on completion. | Scheduled |
| Protection | How it works |
|---|---|
| Authentication | Email and password for admin access. Magic-link tokens for client intake, hashed at rest, with 14-day sliding expiry and instant revocation. |
| Tenant isolation | Every workspace's data is scoped at the database query layer. Cross-tenant access is impossible by construction, not by convention. |
| Audit logging | Every field edit, override, routing decision, and admin action recorded with editor, timestamp, and version. Exportable for compliance review. |
| Voice call recording | Recordings and transcripts encrypted at rest. Retention configurable per workspace. TCPA-compliant consent capture at call start. |
| Subprocessor list | Available on request and updated when material changes occur. We notify customers in advance of any subprocessor change that affects data handling. |
| Data residency | US data centers by default. EU residency for Advanced-tier customers with the requirement. |
| Backup and recovery | Continuous database replication. Off-platform encrypted backups with 30-day retention and tested restore procedures. |
| SSO and access reviews | SAML and OIDC SSO (Google, Microsoft, Okta) plus quarterly automated access reviews on the Advanced tier. |
If you discover a vulnerability, report it directly to security@northernplus.com. We acknowledge reports within one business day, triage within three, and disclose responsibly with credit to the reporter when desired.
We respond to security and procurement questionnaires within five business days. Bring yours to your demo or send it ahead to security@northernplus.com.
Analytics stay off until you choose.
We use cookies to improve the site. Read our Privacy Policy to learn more.