Compliance
Paradigm maintains a strong compliance framework grounded in recognized industry standards.

SOC 2 Type 2
Paradigm's SOC 2 Type 2 report covers Security, Confidentiality, and Availability, and is audited annually.

SOC 3
Paradigm's SOC 3 report is a publicly available version of our SOC 2 that covers the same trust services criteria.
GDPR
Paradigm is GDPR compliant and is committed to processing personal data lawfully and transparently.

ISO 27001
Our platforms are hosted on Amazon Web Services (AWS), which maintains ISO 27001 certification.
Responsible AI
Paradigm develops and deploys AI technologies ethically, transparently, and responsibly.

CCPA
Paradigm complies with the CCPA by maintaining appropriate policies, processes, and safeguards to protect personal information.
Monitoring
Paradigm maintains a comprehensive set of security, privacy, and operational policies that are continuously monitored and enforced to protect customer data. Our policies are reviewed on an ongoing basis to ensure they remain effective and aligned with evolving risk and compliance standards. All data is housed in physically secure, US-based AWS data centers across multiple availability zones.
Subprocessors

AWS
Cloud Hosting Services.

Stripe, Inc.
Payment, Invoicing, and Subscriptions.

Google Inc.
Encrypted document storage and sharing in the cloud.

Microsoft Corporation
Encrypted document storage and sharing in the cloud.

Box, Inc.
Encrypted document storage and sharing in the cloud.

Posit Software, PBC (formerly known as RStudio)
Analyze data.

Qualtrics International Inc.
Administer and analyze survey data

Zoom Communications
Video, audio, phone, and chat communications platform.

OpenAI
AI platform for Blueprint and Reach Products.
Resources
Get our latest security and compliance resources and reports
SOC 2 Type II Report
Paradigm's SOC 2 Type 2 report covers the trust services categories of Security, Confidentiality, and Availability, and is audited annually. NDA is required.
SOC 2 Type III Report
Paradigm's SOC 3 report is a publicly available version of our SOC 2 that covers the same trust services criteria.
Data Processing Addendum (DPA)
Paradigm's Data Processing Addendum (DPA) is a supplemental agreement that sets out the parties’ respective obligations for the processing, protection, and lawful handling of personal data under applicable data protection laws.
Penetration Test for Reach Platform
A Confirmation Penetration Test Certificate for Paradigm's Reach Platform.
Penetration Test for Blueprint Platform
A Confirmation Penetration Test Certificate for Paradigm's Blueprint Platform.
AI Addendum
A supplemental agreement that governs the use of artificial intelligence features within the services, including how AI-generated outputs are produced, reviewed, and used by the customer.
Paradigm Terms of Service
Paradigm’s Terms of Service governing the use of our platform and services, including data protection, confidentiality, and security obligations
Privacy Policy
Paradigm’s Privacy Policy explains how we collect, use, process, and protect personal data in connection with our products and services.
Get Additional Support
Have additional questions? Reach out to our highly-trained support team to get answers to your security and compliance questions at [email protected]
