Skip to content

Enterprise > Security and compliance

Derp Trust Center

Open in ChatGPT ↗
Ask ChatGPT about this page
Open in Claude ↗
Ask Claude about this page
Copied!

Access Derp's security documentation, compliance certifications, and third-party assessment resources to complete your vendor security review.

Derp's Trust Center is the central hub for security documentation, compliance certifications, and third-party assessments. It provides the information security teams, procurement, and compliance officers need to evaluate Derp as a vendor and complete security reviews.

Derp is SOC 2 Type II certified, demonstrating compliance with industry-standard security controls across the following trust service criteria:

  • Security - Infrastructure protection, access controls, and monitoring
  • Availability - System uptime and disaster recovery
  • Confidentiality - Data protection and privacy controls
  • Processing integrity - Accurate, complete, and authorized processing

Requesting SOC 2 reports: Enterprise customers can request SOC 2 reports directly through the Trust Center portal, through their account manager, or by emailing security@derp.dev.

Derp publishes a list of subprocessors — third-party service providers that process data on Derp's behalf. This includes infrastructure providers, LLM providers, and other services that support Derp's operations.

View the current list of subprocessors at Derp subprocessors list.

The following resources provide detailed information about Derp's security practices:

  • Trust Center portal - External portal with downloadable compliance reports and real-time security status
  • Security overview - Derp's security architecture, data handling, and compliance certifications
  • Privacy policy - How Derp collects, uses, and protects personal data
  • Subprocessors - Third-party service providers that process data on Derp's behalf

If you're conducting a vendor security assessment or completing a compliance questionnaire, Derp can provide:

  • SOC 2 Type II reports - Available upon request for Enterprise customers
  • Compliance questionnaire assistance - Derp's security team can help complete vendor security questionnaires
  • Architecture and deployment - Details about Derp's infrastructure, deployment models, and data flows

To request any of these materials, contact your account manager or email security@derp.dev.

Penetration testing and vulnerability management

Section titled “Penetration testing and vulnerability management”

Derp conducts regular security assessments as part of its SOC 2 program. The details of Derp's vulnerability management and penetration testing practices are validated through its SOC 2 Type II certification.

If you discover a security vulnerability in Derp, please report it responsibly:

  1. Email security@derp.dev with detailed steps to reproduce the issue.
  2. Allow Derp time to investigate and address the vulnerability before any public disclosure.

Derp works with reporters to coordinate disclosure timelines.