Continuum API

Trust Center

Continuum's compliance posture, security controls, and enterprise features — current as of August 2026.

Live
In progress
Planned

Compliance

DPA available, SCCs in place for EU data transfers

Live

Data subject rights honored; privacy policy updated Aug 2026

Live
SOC 2 Type I

Audit underway; report expected Q1 2027

In progress
SOC 2 Type II

Planned following Type I certification

Planned

Security

Encryption in transit (TLS 1.2+)

All API and dashboard traffic encrypted

Live
Encryption at rest (AES-256)

Database volumes and storage encrypted at rest

Live
API key hashing (SHA-256)

Keys hashed before storage, never logged in full

Live
MFA enforcement

MFA enforced for all staff; org admins can enforce for members

Live
Row-level security

Database RLS ensures customer data isolation

Live
Annual penetration test

Report available to enterprise customers under NDA

Live
Dependency vulnerability scanning

GitHub Dependabot + secret scanning enabled on all repos

Live

Enterprise

Okta, Azure AD, Google Workspace, and any SAML IdP

Live
SCIM directory sync

Auto-provision and deprovision via Okta / Azure AD

Live
Audit logs

Tamper-evident logs for all sensitive actions, exportable

Live
Member RBAC

Admin and member roles with permission enforcement

Live

Bonterms-based DPA, countersign available on request

Live

Published and kept current; 10-day notice on changes

Live

Full technical and organizational measures document

Live
Custom data retention

Configurable retention periods per customer

Planned

Need a Security Questionnaire completed, a countersigned DPA, or a pen test report?

Contact security@continuumapi.com