NorthernPlus
Security and Trust

Lead and client data is sensitive on a different scale than in typical SaaS.

NorthernPlus is built so that staying compliant is the path of least resistance. We built to the legal industry's compliance bar first, one of the most demanding there is, and that posture now protects every company we serve. Below is a straight snapshot of where we are today.

1

Where we are today

We do not oversell what we have. Each item below carries its real status.

ItemWhere it standsStatus
SOC 2 Type IIAudit window underway. We can share our current control framework, monitoring posture, and progress under NDA during a procurement review.Pending
HIPAA-aligned postureEncryption, access controls, audit logging, and data segregation align with HIPAA Security Rule requirements. BAA execution available on the Advanced tier; full BAA-eligible posture across all subprocessors is on the roadmap.Today
Encryption in transitTLS 1.3 across every surface: client intake, admin console, voice agent, and integrations. No exceptions.Today
Encryption at restAES-256 at rest across application database, file storage, and backups. Field-level encryption for sensitive intake data is on the roadmap.Today
Right to be forgottenTwo-click client redaction for GDPR and CCPA requests. PII is scrubbed in place; engagement audit trails are preserved per your industry's recordkeeping requirements.Today
Penetration testingIndependent third-party penetration test scheduled. Report available to enterprise customers under NDA on completion.Scheduled

2

The protections, in plain language

ProtectionHow it works
AuthenticationEmail and password for admin access. Magic-link tokens for client intake, hashed at rest, with 14-day sliding expiry and instant revocation.
Tenant isolationEvery workspace's data is scoped at the database query layer. Cross-tenant access is impossible by construction, not by convention.
Audit loggingEvery field edit, override, routing decision, and admin action recorded with editor, timestamp, and version. Exportable for compliance review.
Voice call recordingRecordings and transcripts encrypted at rest. Retention configurable per workspace. TCPA-compliant consent capture at call start.
Subprocessor listAvailable on request and updated when material changes occur. We notify customers in advance of any subprocessor change that affects data handling.
Data residencyUS data centers by default. EU residency for Advanced-tier customers with the requirement.
Backup and recoveryContinuous database replication. Off-platform encrypted backups with 30-day retention and tested restore procedures.
SSO and access reviewsSAML and OIDC SSO (Google, Microsoft, Okta) plus quarterly automated access reviews on the Advanced tier.

3

Vulnerabilities and questionnaires

If you discover a vulnerability, report it directly to security@northernplus.com. We acknowledge reports within one business day, triage within three, and disclose responsibly with credit to the reporter when desired.

Good-faith research is safe here. We do not pursue legal action against good-faith security research conducted under standard responsible-disclosure norms.

We respond to security and procurement questionnaires within five business days. Bring yours to your demo or send it ahead to security@northernplus.com.

Ready to look deeper? We will walk the platform with your compliance requirements in mind. Schedule a demo