Skip to main content
Exterro logo

Exterro

Regulatory evidence

Turn data risk into confidence with Exterro's AI-driven platform for eDiscovery, digital forensics, data privacy, security &

exterro.comLegal techLast verified 21 Sep 2026

Exterro against third-party requirements

For each regulation, how many of the requirements it places on your vendors Exterro’s public evidence reaches. Open one for every item with its date and source.

Documents on the trust centre

What the vendor lists, typed; public items can be read now, the rest are available on request.

11 documents listed on Exterro’s trust centre

trustcenter.exterro.com
  • SOC 2 bridge letter
    • Exterro SOC2 Bridge Letteron request · seen 21 Sep 2026
  • Business continuity and disaster recovery plan
    • 2025 BCP Test Summaryon request · seen 21 Sep 2026
    • 2025 Exterro Disaster Recovery Test Resultson request · seen 21 Sep 2026
    • Business Continuity Disaster Recovery Policyon request · seen 21 Sep 2026
  • HITRUST report
    • 2026 Exterro HITRUST e1on request · seen 21 Sep 2026
  • ISO certificate
    • Exterro ISO 27001 Certificateon request · seen 21 Sep 2026
  • Penetration test report
    • 2024 Exterro Penetration Teston request · seen 21 Sep 2026
    • 2025 Exterro Penetration Teston request · seen 21 Sep 2026
  • Security questionnaire (SIG, CAIQ, HECVAT)
    • Exterro SIG Questionnaireon request · seen 21 Sep 2026
  • Security policy or overview
    • Exterro Cloud Security Overviewon request · seen 21 Sep 2026
  • SOC 2 report
    • 2025 Exterro SOC 2 Type II Reporton request · seen 21 Sep 2026

What the vendor says

Answers the vendor publishes to questions buyers ask, quoted with the link to where it says so.

  • Where data is hosted or processed

    Where is customer data stored and processed?

    SendSafely hosts its infrastructure with multi-tenant, outsourced data center providers. They use Amazon Web Services (AWS) for their infrastructure. The physical and environmental security controls of these providers are audited for SOC 2 Type II and ISO 27001 compliance.

    as of 21 Sep 2026Source

  • International data transfers

    How does SendSafely comply with GDPR for EU/UK data transfers?

    SendSafely implements appropriate safeguards for international data transfers: - For UK transfers: They use the UK International Data Transfer Addendum to the EU Standard Contractual Clauses - For EEA/Switzerland transfers: They implement the EU Standard Contractual Clauses - Module Two (Controller-to-Processor) applies when the customer is a controller - Module Three (Processor-to-Processor) applies when the cust...

    Regions named: EU, UK, Switzerlandas of 21 Sep 2026Source

  • Encryption

    What encryption methods does SendSafely use?

    SendSafely uses the OpenPGP message format with 256-bit AES encryption. Their encryption process involves: - A 256-bit random secret value generated by their servers (Server Secret) - A 256-bit random secret value generated by your machine (Client Secret) - These values are combined to create the encryption key using OpenPGP's Iterated and Salted String-to-key specifier - All communications between SendSafely serv...

    as of 21 Sep 2026Source

  • Data retention and deletion

    What is SendSafely's data retention policy?

    Personal data provided to SendSafely is retained only as long as necessary to provide the services. SendSafely performs backup copies for possible restoration requirements. Any data that is erased at the end of its retention period is erased using techniques that make it impossible to reconstruct, including backup copies after their retention period.

    as of 21 Sep 2026Source

  • Notice of subprocessor changes

    How will customers be notified of future subprocessor changes?

    Exterro will notify customers of any future subprocessor changes through: - Direct email notifications to designated contacts - Updates to our subprocessor list in our Trust Center https://trustcenter.exterro.com

    as of 21 Sep 2026Source

All articles

This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.