SOC 2
Parley undergoes System and Organization Controls (SOC) 2 Type 2 audits of the design and operating effectiveness of our security controls.GDPR
Parley is compliant with the EU General Data Protection Regulation (GDPR). We act as a data processor for the personal data our customers store in Parley, and we support our customers in meeting their obligations as data controllers. For personal data transferred from the EU, the UK, and Switzerland, Parley is certified under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework, and uses Standard Contractual Clauses where another transfer mechanism is required. See our Privacy Policy for details. Contact us if you require a Data Processing Agreement (DPA) or have questions about how we handle personal data.Your data
Your firm owns its data. Everything your team uploads to Parley, and everything Parley generates from it, remains your firm’s property and is treated as your confidential information. We never use your content or generated work product to train, fine-tune, or otherwise develop AI models that are deployed for or accessible to other customers.Security controls
Our security program includes:- Encryption of data in transit and at rest
- Multi-factor authentication and least-privilege access, with regular access reviews
- Automated backups and tested disaster recovery plans
- Centralized audit logging, monitoring, and a documented incident response and breach notification process
- Annual penetration testing, continuous vulnerability scanning, and automated patching
- Confidentiality agreements and annual security training for all personnel
