Trust Center

Everything Sledge does to protect your data

This is where the detail lives: the assessments Sledge holds, the documents your security team will ask for, how Sledge handles your data topic by topic, and the third parties that touch it. Every claim here is one the security team has confirmed is true today.

Sledge security

Secure

Point at a shield to see what it covers.

Documents

The security program

What Sledge does, topic by topic. No pass/fail grid โ€” Sledge will add one when a monitoring tool actually verifies each control continuously.

Infrastructure security

  • AES-256 encryption at rest, TLS 1.2+ in transit
  • Data scoped to your organization, with least-privilege access
  • Private networking, managed firewalls and DDoS protection
  • Hosted in established enterprise cloud data centers

Every byte you store in Sledge is encrypted the moment it lands and stays encrypted at rest. Production runs inside private networks with no direct public access, in established enterprise cloud data centers.

Also true
  • Keys managed by a dedicated key-management service with rotation
  • Encrypted, geographically redundant backups
  • Hardened, regularly patched server images
  • Infrastructure-as-code with peer-reviewed changes
  • Segregated staging and production environments
  • DDoS mitigation and WAF at the network edge
Inherited from our enterprise cloud hosting.

Data and privacy

  • Retention and deletion procedures established
  • Deleted on request per GDPR and CCPA
  • Data classification policy enforced
  • Never sold or used to train third-party models

Your data is yours. Sledge never sells it and never uses it to train third-party AI models. You decide how long it is kept and can export or delete it on request, in line with GDPR and CCPA.

Also true
  • Data Processing Addendum available on request
  • Documented data retention schedule
  • Right to access, export and erasure honored
  • Data minimization โ€” we collect only what we need
  • Privacy reviews for new features
Aligned to GDPR, CCPA and industry data-handling norms.

Payments and billing

  • Card payments handled by a specialist payment provider
  • Card numbers never touch Sledge servers
  • Tokenized, vaulted payment methods
  • Fraud monitoring on every transaction

Payments are processed by a specialist payment provider. Your full card number never touches Sledge servers โ€” we only ever see a secure token, so there is nothing sensitive for us to lose.

Also true
  • 3-D Secure and strong customer authentication
  • Tokenized cards stored in the processor vault, not Sledge
  • Real-time fraud and anomaly monitoring
Handled by our payment processor, not by Sledge.

Authentication and accounts

  • SSO and SAML for enterprise accounts
  • Enforced MFA and strong password policy
  • Managed, industry-standard auth provider
  • Session, device and audit logging

Sign-in is handled by a managed identity platform with enterprise SSO, SAML and enforced multi-factor authentication. Every session, device and admin action is logged so you always know who did what.

Also true
  • SCIM provisioning and de-provisioning
  • Role-based access control with granular permissions
  • Configurable session timeouts
  • Full authentication audit trail
Built on a managed authentication platform.

Product security

  • CASA Tier 2 assessment against OWASP ASVS
  • Annual third-party penetration testing
  • Continuous dependency and code scanning in CI/CD
  • Secure SDLC with mandatory peer review

Security is built into how we ship. Sledge has completed a CASA Tier 2 assessment against the OWASP ASVS, runs annual third-party penetration tests, and scans every code change and dependency before it reaches production.

Also true
  • Mandatory peer review on all code
  • Automated static and dependency scanning in CI/CD
  • Secrets scanning to prevent leaked credentials
  • Responsible disclosure program
  • Remediation SLAs by severity
Source and CI/CD on managed platforms.

Continuous monitoring

  • 24/7 threat detection and alerting
  • Centralized, automated log analysis
  • Documented, tested incident response plan
  • Automated backups and point-in-time recovery

We watch our systems around the clock. Centralized logs feed automated detection and alerting, and a documented, regularly tested incident response plan means we react fast when something looks off.

Also true
  • On-call rotation with defined escalation paths
  • Point-in-time recovery and tested restores
  • Post-incident reviews with corrective actions
  • Uptime and status published publicly
  • Anomaly detection on access patterns
Backed by enterprise monitoring and logging tooling.
View the status page (opens in a new tab)

Availability and resilience

  • Runs across multiple availability zones
  • Automated daily backups with point-in-time recovery
  • 99.9% uptime target with a public status page
  • Continuity and disaster recovery plans tested regularly

Sledge runs across multiple availability zones, so a single failure does not take your jobs offline. Backups run daily with point-in-time recovery, uptime is published, and the continuity and recovery plans are tested rather than filed away.

Also true
  • Tested restores, not just scheduled backups
  • Documented recovery time and recovery point objectives
  • Live status page for incidents and maintenance
  • Redundant, geographically separated storage
Runs on multi-zone enterprise cloud infrastructure.
View the status page (opens in a new tab)

AI controls

  • Your data never trains third-party models
  • Human review of AI-suggested actions
  • Scoped, least-privilege access for AI processing
  • AI providers held to the same data standards

Sledge uses AI to remove busywork, not to expose your data. Your information is never used to train third-party models, AI access is scoped to the minimum needed, and consequential actions stay under human review.

Also true
  • AI subprocessors bound by the same data terms
  • No training on customer data, contractually enforced
  • Audit trail on AI-assisted actions
  • Clear indication when AI is involved
Governed by our data-handling and privacy policies.

Organizational security

  • Background checks on personnel
  • Annual security and privacy training
  • Enforced MFA on all internal systems
  • Vendor security review before onboarding

People and process are part of security too. Sledge runs background checks on personnel, requires annual security and privacy training, enforces MFA on internal systems, and reviews every vendor before onboarding.

Also true
  • Least-privilege internal access, reviewed regularly
  • Formal onboarding and offboarding procedures
  • Written security policies reviewed annually
  • Confidentiality obligations for all staff
Mapped to SOC 2 organizational controls.

Subprocessors

Who processes your data on Sledge's behalf, and where.

Cloud hosting and storage

Your data is stored in the United States, encrypted, on an established cloud provider that runs its own audited security program.

Data
Encrypted application data and backups
Region
United States

Database and sign-in

Your account and sign-in details are held in the United States by a managed database and authentication provider.

Data
Account records and sign-in credentials
Region
United States

Application hosting and delivery

The Sledge app is served from infrastructure in the United States.

Data
App delivery and request logs
Region
United States

AI processing

Anything you send to an AI feature is processed in the United States and is not used to train third-party models.

Data
Content you send to AI features
Region
United States

Payments

Payments run through a specialist payment provider. Your full card number never reaches Sledge servers.

Data
Billing details and payment methods
Region
United States

Email and messaging delivery

Notifications Sledge sends on your behalf are delivered by providers in the United States.

Data
Notification and message delivery
Region
United States

Last reviewed August 2026. The full named list is available on request โ€” .

Frequently asked questions

No. Sledge does not sell your data, does not hand it to advertisers, and does not use it to train third-party AI models. Your data is in Sledge to run your business.

Didn't find your answer?

Ask and a person on the Sledge security team will answer. Questions go to Sledge, not to an analytics tool.

This Trust Center was last reviewed on August 20, 2026. Sledge shows a date, not a live verification indicator, because no monitoring tool drives one yet.

Run your back office on software you can vouch for

Independently assessed. No contracts. No setup fees.

Trust Center | Sledge