Trust Center

Security you can verify — not just claims.

Trust is the foundation of what we do. This page lays out how we protect your data, the standards our controls are built around, and how to request documentation for your own due diligence.

Philotech team members meeting to review compliance and security standards
How we protect you

The standards behind every Philotech engagement.

ISO 27001-aligned practices

Our information-security program is built around the ISO 27001 framework — risk assessment, documented controls, and continuous monitoring across service delivery.

Controls mapped to SOC 2 & HIPAA

We implement and document controls mapped to SOC 2 (security, availability, confidentiality) and HIPAA safeguards for protected health information — the evidence auditors and insurers request.

FTC Safeguards & DOL guidance

For financial, accounting, benefits, and TPA firms, our controls and documentation map to FTC Safeguards and DOL cybersecurity guidance.

HIPAA Business Associate Agreement

For healthcare and other regulated clients handling PHI, Philotech executes a HIPAA Business Associate Agreement (BAA) as part of onboarding.

Built on trusted enterprise platforms

Enterprise technology, professionally run.

Microsoft 365

Identity, productivity, and security — managed end to end for your team.

Bitdefender

Enterprise endpoint protection and managed detection & response powering every PhiloSecure plan — including MESH, its email-security layer that filters phishing and payment-fraud attempts before they reach the inbox.

Cove Data Protection

Immutable, cloud-first backup and disaster recovery built for SMBs.

1Password

Business password management, available on all plans, to eliminate the reused and weak credentials behind most breaches.

Compliance

Requesting documentation.

For due diligence, vendor assessments, or regulatory audits, our team can provide documentation covering our security posture and controls. Depending on what your reviewers need, that can include a security overview, our control mappings, a HIPAA Business Associate Agreement, proof of cyber-liability insurance, and completed security questionnaires — shared under NDA where appropriate.

Contact us to request documentation →

Security questions before you buy? Good.

The firms that ask the hardest questions make the best clients. Bring yours.

Talk to Our Team