Compliance
Paradigm maintains a strong compliance framework grounded in recognized industry standards.

SOC 2 Type 2
Paradigm's SOC 2 Type 2 report covers Security, Confidentiality, and Availability, and is audited annually.

SOC 3
Paradigm's SOC 3 report is a publicly available version of our SOC 2 that covers the same trust services criteria.
GDPR
Paradigm is GDPR compliant and is committed to processing personal data lawfully and transparently.
Responsible AI
Paradigm develops and deploys AI technologies ethically, transparently, and responsibly.

CCPA
Paradigm complies with the CCPA by maintaining appropriate policies, processes, and safeguards.
Monitoring
Paradigm maintains a comprehensive set of security, privacy, and operational policies that are continuously monitored and enforced to protect customer data. Our policies are reviewed on an ongoing basis to ensure they remain effective and aligned with evolving risk and compliance standards. All data is housed in physically secure, US-based AWS data centers across multiple availability zones.
Subprocessors

Amazon Web Services, Inc.
Cloud Hosting Services

Railway Corp.
Cloud Infrastructure & Deployment Platform for Surface

Posit Software, PBC
Data Analytics Platform

OpenAI OpCo, LLC
AI Processing Services

Anthropic, PBC
AI Processing Services

Unstructured Technologies, Inc.
Unstructured Data Processing & ETL Platform

Braintrust Data, Inc.
AI Evaluation & Observability Platform

Qualtrics International Inc.
Survey & Feedback Platform

Momentive Global Inc. (SurveyMonkey)
Survey & Feedback Platform
Resources
Get our latest security and compliance resources and reports
SOC 2 Type II Report
SOC 2 Type 2 report covers the trust services categories of Security, Confidentiality, and Availability, and is audited annually. NDA is required.
SOC 2 Type III Report
SOC 3 report is a publicly available version of our SOC 2 that covers the same trust services criteria.
Data Processing Addendum (DPA)
The Data Processing Addendum (DPA) is a supplemental agreement that sets out the respective obligations for the processing, protection, and lawful handling of personal data under applicable data protection laws.
Surface Security Privacy and AI Governance Overview
Paradigm's security controls, privacy practices, AI governance approach, and platform overview for Surface.
Penetration Test for Reach Platform
A confirmation certificate showing that Reach Platform has undergone and passed a penetration test.
AI Addendum
A supplemental agreement that governs the use of artificial intelligence features within the services, including how AI-generated outputs are produced, reviewed, and used by the customer.
Paradigm Terms of Service
Terms of Service govern the use of our platform and services, including data protection, confidentiality, and security obligations.
Privacy Policy
The Privacy Policy explains how we collect, use, process, and protect personal data in connection with our products and services.
Get Additional Support
Have additional questions? Reach out to our highly-trained support team to get answers to your security and compliance questions at [email protected]
