Enterprise > Security and compliance
Derp Trust Center
# Derp Trust Center Derp's [Trust Center](https://trust.derp.dev) is the central hub for security documentation, compliance certifications, and third-party assessments. It provides the information security teams, procurement, and compliance officers need to evaluate Derp as a vendor and complete security reviews. ## Compliance certifications ### SOC 2 Type II Derp is **SOC 2 Type II certified**, demonstrating compliance with industry-standard security controls across the following trust service criteria: * **Security** - Infrastructure protection, access controls, and monitoring * **Availability** - System uptime and disaster recovery * **Confidentiality** - Data protection and privacy controls * **Processing integrity** - Accurate, complete, and authorized processing **Requesting SOC 2 reports:** Enterprise customers can request SOC 2 reports directly through the [Trust Center portal](https://trust.derp.dev), through their account manager, or by emailing [security@derp.dev](mailto:security@derp.dev). ## Subprocessors Derp publishes a list of subprocessors — third-party service providers that process data on Derp's behalf. This includes infrastructure providers, LLM providers, and other services that support Derp's operations. View the current list of subprocessors at [Derp subprocessors list](https://www.derp.dev/legal/subprocessors). :::note Derp maintains **Zero Data Retention (ZDR)** agreements with its contracted LLM providers (Anthropic, OpenAI, Google), meaning they do not store or train on your data. ::: ## Security documentation The following resources provide detailed information about Derp's security practices: * **[Trust Center portal](https://trust.derp.dev)** - External portal with downloadable compliance reports and real-time security status * **[Security overview](/enterprise/security-and-compliance/security-overview/)** - Derp's security architecture, data handling, and compliance certifications * **[Privacy policy](https://www.derp.dev/legal/privacy-policy)** - How Derp collects, uses, and protects personal data * **[Subprocessors](https://www.derp.dev/legal/subprocessors)** - Third-party service providers that process data on Derp's behalf ## Requesting security information If you're conducting a vendor security assessment or completing a compliance questionnaire, Derp can provide: * **SOC 2 Type II reports** - Available upon request for Enterprise customers * **Compliance questionnaire assistance** - Derp's security team can help complete vendor security questionnaires * **[Architecture and deployment](/enterprise/enterprise-features/architecture-and-deployment/)** - Details about Derp's infrastructure, deployment models, and data flows To request any of these materials, contact your account manager or email [security@derp.dev](mailto:security@derp.dev). ## Penetration testing and vulnerability management Derp conducts regular security assessments as part of its SOC 2 program. The details of Derp's vulnerability management and penetration testing practices are validated through its SOC 2 Type II certification. ### Responsible disclosure If you discover a security vulnerability in Derp, please report it responsibly: 1. Email [security@derp.dev](mailto:security@derp.dev) with detailed steps to reproduce the issue. 2. Allow Derp time to investigate and address the vulnerability before any public disclosure. Derp works with reporters to coordinate disclosure timelines.Access Derp's security documentation, compliance certifications, and third-party assessment resources to complete your vendor security review.
Derp's Trust Center is the central hub for security documentation, compliance certifications, and third-party assessments. It provides the information security teams, procurement, and compliance officers need to evaluate Derp as a vendor and complete security reviews.
Compliance certifications
Section titled “Compliance certifications”SOC 2 Type II
Section titled “SOC 2 Type II”Derp is SOC 2 Type II certified, demonstrating compliance with industry-standard security controls across the following trust service criteria:
- Security - Infrastructure protection, access controls, and monitoring
- Availability - System uptime and disaster recovery
- Confidentiality - Data protection and privacy controls
- Processing integrity - Accurate, complete, and authorized processing
Requesting SOC 2 reports: Enterprise customers can request SOC 2 reports directly through the Trust Center portal, through their account manager, or by emailing security@derp.dev.
Subprocessors
Section titled “Subprocessors”Derp publishes a list of subprocessors — third-party service providers that process data on Derp's behalf. This includes infrastructure providers, LLM providers, and other services that support Derp's operations.
View the current list of subprocessors at Derp subprocessors list.
Security documentation
Section titled “Security documentation”The following resources provide detailed information about Derp's security practices:
- Trust Center portal - External portal with downloadable compliance reports and real-time security status
- Security overview - Derp's security architecture, data handling, and compliance certifications
- Privacy policy - How Derp collects, uses, and protects personal data
- Subprocessors - Third-party service providers that process data on Derp's behalf
Requesting security information
Section titled “Requesting security information”If you're conducting a vendor security assessment or completing a compliance questionnaire, Derp can provide:
- SOC 2 Type II reports - Available upon request for Enterprise customers
- Compliance questionnaire assistance - Derp's security team can help complete vendor security questionnaires
- Architecture and deployment - Details about Derp's infrastructure, deployment models, and data flows
To request any of these materials, contact your account manager or email security@derp.dev.
Penetration testing and vulnerability management
Section titled “Penetration testing and vulnerability management”Derp conducts regular security assessments as part of its SOC 2 program. The details of Derp's vulnerability management and penetration testing practices are validated through its SOC 2 Type II certification.
Responsible disclosure
Section titled “Responsible disclosure”If you discover a security vulnerability in Derp, please report it responsibly:
- Email security@derp.dev with detailed steps to reproduce the issue.
- Allow Derp time to investigate and address the vulnerability before any public disclosure.
Derp works with reporters to coordinate disclosure timelines.