Skip to main content
CircleCo logo

CircleCo

Regulatory evidence

Build a home for your community, events, and courses — all under your own

circle.soLast verified 21 Sep 2026

CircleCo against third-party requirements

For each regulation, how many of the requirements it places on your vendors CircleCo’s public evidence reaches. Open one for every item with its date and source.

Documents on the trust centre

What the vendor lists, typed; public items can be read now, the rest are available on request.

11 documents listed on CircleCo’s trust centre

trust.circle.so
  • AI policy or governance framework
    • AI Policypublic · seen 21 Sep 2026
  • Business continuity and disaster recovery plan
    • Business Continuity and Disaster Recovery Planon request · seen 21 Sep 2026
  • Incident response plan
    • Incident Response Planon request · seen 21 Sep 2026
  • Security policy or overview
    • Access Control Policyon request · seen 21 Sep 2026
    • Cryptography Policyon request · seen 21 Sep 2026
    • Human Resource Security Policyon request · seen 21 Sep 2026
    • Information Security Policy (AUP)on request · seen 21 Sep 2026
    • Operations Security Policyon request · seen 21 Sep 2026
    • Secure Development Policyon request · seen 21 Sep 2026
  • SOC 2 report
    • SOC 2 Type II Attestationpublic · seen 21 Sep 2026
  • SOC 3 report
    • SOC 3 (Full report)public · seen 21 Sep 2026

What the vendor says

Answers the vendor publishes to questions buyers ask, quoted with the link to where it says so.

  • Where data is hosted or processed

    Where can I find Circle's Data Processing Addendum (DPA)?

    Circle's DPA can be found at https://circle.so/dpa. Our DPA binds Circle to appropriate security, prompt breach notification, cooperation with you and regulators, assistance with data-subject requests, and flow-down obligations to sub-processors. These practices are compliant with the GDPR.

    as of 21 Sep 2026Source

  • Where data is hosted or processed

    Where does Circle host customer data?

    Circle hosts all data in AWS US-East-1 (Northeast US). Please note that Circle doesn't currently offer the option to host data in any other locations. This means that by using Circle's services, personal data will be processed in the United States. All such transfers are covered by our Data Processing Addendum (DPA), which includes the EU Standard Contractual Clauses, the UK Addendum, and the Swiss Addendum to ens...

    Regions named: EU, UK, USas of 21 Sep 2026Source

  • Encryption

    How does Circle encrypt customer data?

    All datastores with customer data, in addition to S3 buckets, are encrypted at rest with strong encryption (AES-256 and B-crypt). Sensitive collections and tables also use row-level encryption. This means the data is encrypted even before it hits the database so that neither physical access, nor logical access to the database, is enough to read the most sensitive information. Circle also uses TLS 1.2 or higher eve...

    as of 21 Sep 2026Source

  • Incident and breach notification

    How quickly will I be notified if a breach involving my data or community data occurs?

    Circle maintains a robust protocol for investigating and reporting security incidents. In the event of a relevant incident, Circle will notify customers (or other affected data subjects, as applicable) without undue delay, as required under applicable privacy laws. More information can be found on this in our DPA (please see references to "Security Incident" throughout the document).

    as of 21 Sep 2026Source

  • Penetration testing

    Does Circle conduct penetration tests?

    Circle engages with one of the best penetration testing consulting firms in the industry at least annually. Our current preferred penetration testing partner is Redseer Security. All areas of the Circle product (web + mobile) and cloud infrastructure are in-scope for these assessments, and source code is fully available to the testers in order to maximize the effectiveness and coverage.

    as of 21 Sep 2026Source

  • Data retention and deletion

    What is the data retention period for information used by AI features?

    Circle retains data according to your contract and standard retention practices (see our Data Processing Addendum). AI model providers do not store or retain Inputs.

    as of 21 Sep 2026Source

All articles

This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.