NEVTAN ENGAGE
Security & Compliance Overview
Last Updated: June 5, 2026
Security, privacy, and reliability are built into the foundation of Engage — not added as afterthoughts. This document provides an overview of Engage's security architecture, operational controls, compliance posture, and customer-facing security features. For contractual commitments, refer to the Engage Data Processing Agreement at engage.nevtan.com/legal/dpa. For live system status, visit status.engage.nevtan.com.
1. Compliance and Certifications
| Framework / Standard | Scope | Status | Notes |
|---|---|---|---|
| GDPR (EU) | Customer data processing | Compliant | DPA and SCCs available. Privacy Policy and DPA updated June 2026. |
| UK GDPR / PECR | Customer data processing | Compliant | UK IDTA addendum available. Cookie Policy addresses PECR requirements. |
| CCPA / CPRA (California) | Customer data processing | Compliant | Service Provider designation confirmed in DPA. No sale or sharing of personal information. |
| CAN-SPAM / TCPA (USA) | Email and SMS channel features | Compliant | Unsubscribe handling and opt-out enforcement built into the platform. |
| CASL | Email / SMS marketing features | Compliant | Express/implied consent tracking, double opt-in, and suppression list tools built in. |
| PIPEDA | All data processing | Compliant | Privacy Officer appointed. Policies updated June 2026. |
| SOC 2 Type II | Platform and infrastructure | In Progress — Q4 2026 | Audit engagement initiated. Controls implemented. Report expected Q4 2026. |
| ISO 27001 | Information security management | Planned — 2027 | Planned following SOC 2 completion. Gap assessment in progress. |
| EU AI Act | AI features | Compliant (current obligations) | No prohibited-risk systems. Transparency obligations met. Monitoring ongoing. |
| PCI DSS | Payment processing | Not Applicable | Engage does not store payment card data. Payments handled by Stripe (PCI DSS Level 1). |
2. Security Design Principles
Security by Design
Security requirements are incorporated at the design stage of every product feature and infrastructure component.
Privacy by Design
Data minimization, purpose limitation, and privacy impact are evaluated during product development.
Least Privilege Access
All access is restricted to the minimum required for a specific function and reviewed regularly.
Defense in Depth
Multiple independent security layers are applied at the network, application, data, and identity levels.
Continuous Monitoring
Production systems are monitored 24/7 for security events, anomalies, and availability.
Secure Development Lifecycle
Security reviews, dependency scanning, and vulnerability assessments are integrated into the software development pipeline.
3. Infrastructure Security
3.1 Hosting
Engage is hosted on Amazon Web Services (AWS). AWS maintains SOC 1, SOC 2, SOC 3, ISO 27001, and PCI DSS Level 1 certifications for its data centres. Physical security is the responsibility of AWS. Customer data is logically isolated between tenants.
3.2 Network Security
3.3 Encryption
In Transit: All communications are encrypted using TLS 1.2 or higher (TLS 1.3 preferred). Supported cipher suites are reviewed annually and weak ciphers are disabled.
At Rest: Customer data is encrypted at rest using AES-256, including databases, object storage, and automated backups.
Key Management: Encryption keys are managed using AWS Key Management Service (KMS). Keys are rotated on a defined schedule and are not stored alongside the data they protect.
3.4 Backup and Disaster Recovery
Automated encrypted backups of all production databases are taken daily. Backups are retained for 30 days in geographically separate storage. Restoration procedures are tested quarterly. For current uptime, visit status.engage.nevtan.com.
4. Identity and Access Management
4.1 Internal Access Controls
4.2 Employee Security
5. Application Security
5.1 Secure Development Lifecycle
5.2 Vulnerability Management
5.3 Monitoring and Logging
6. Incident Response
Engage maintains a documented Incident Response Plan covering detection, triage, containment, investigation, remediation, recovery, and post-incident review.
6.1 Customer Notification
In the event of a Personal Data Breach, Engage notifies affected Account Owners within 48 hours of confirming the breach. Notifications include: the nature of the incident, categories of data affected, steps taken to contain and remediate, and recommended Customer actions. This timeline is designed to provide Customers subject to GDPR's 72-hour authority notification requirement with sufficient lead time.
7. Customer-Facing Security Controls
| Security Feature | Available On | Notes |
|---|---|---|
| Multi-Factor Authentication (MFA) | All plans | TOTP and SMS verification supported. Mandatory MFA enforcement available for organization admins. |
| Single Sign-On (SSO) via SAML 2.0 | Pro and Enterprise | Okta, Azure AD, Google Workspace, and any SAML 2.0-compatible identity provider. |
| Role-Based Access Control (RBAC) | All plans | Owner, Admin, Editor, and Viewer roles. Custom roles on Enterprise plans. |
| Audit Log | Pro and Enterprise | Immutable log of all account actions. Exportable via API. |
| API Key Management | All plans | Scoped API keys with read/write/admin permissions. Rotation and revocation at any time. |
| IP Allowlisting | Enterprise | Restrict dashboard and API access to specified IP ranges. |
| Session Management and Timeout | All plans | Configurable session expiry. Admins can terminate active sessions remotely. |
| Webhook Signature Verification | All plans | All outbound webhooks signed with HMAC-SHA256. |
| Data Export and Deletion Controls | All plans | Account Owners can export all Customer Data at any time and request permanent deletion. |
8. Security Resources
9. Vulnerability Disclosure Policy
9.1 Reporting
Report suspected vulnerabilities to security@engage.nevtan.com. Include: description and potential impact, steps to reproduce, affected URL or component, and contact information. PGP key available at engage.nevtan.com/security/pgp.
9.2 Safe Harbour
Engage will not pursue legal action against researchers who report in good faith, do not access Customer data beyond what is necessary to demonstrate a vulnerability, do not disrupt availability, and allow 90 days for coordinated disclosure.
9.3 Response SLAs
10. Contact
Security Team
Email: security@engage.nevtan.com