Trust & Compliance
Sightline helps you prove your compliance — so we hold ourselves to the same standard, and we run Sightline on Sightline. Here is exactly how we protect your data, and where we stand against every framework we help you assess. We label status honestly and never claim a certification we don't hold.
How we protect your data
Status legend
Govern, identify, protect, detect, respond, recover across our own systems.
Our internal program is structured on CSF 2.0 — the same spine we assess you against.
Lawful processing, data-subject rights, security of processing (Art. 32), 72-hour breach notice.
Data minimization, encryption, access controls, export/erasure, and a breach process are in place. DPA available.
Administrative, physical, and technical safeguards for ePHI; BAAs.
Encryption, access control, audit controls, and a Business Associate Agreement are available for healthcare customers.
Independent attestation of trust-services controls.
We run continuous self-assessment today; an external Type II audit is on the roadmap.
A certified Information Security Management System.
Our ISMS follows 27001; accredited certification is on the roadmap.
Protect student education records; reasonable safeguards; disclosure limits.
For education customers: data is minimized, encrypted, access-controlled, and never used beyond providing the service.
Protect cardholder data.
Sightline never stores cardholder data — payments run through a PCI-certified processor. We never touch card numbers.
Protect FCI/CUI for defense work.
Relevant only for defense customers; we do not claim CMMC certification today.
Firewalls, secure config, patching, access control, malware protection.
These five controls are in place across our systems.
Eight mitigation strategies (MFA, patching, backups, least privilege).
MFA, patching, least-privilege admin, and regular backups are enforced.
Risk management and incident reporting for in-scope entities.
Risk management, supply-chain diligence, and incident handling are in place.
Lawful processing of digital personal data; security safeguards; breach notice.
Consent/notice handling, security safeguards, and a breach process for data principals in India.
Seven personal-data principles incl. security and retention.
Security, retention, and access principles are implemented for Malaysian data.
How to vet us
We back every status above with evidence. To vet Sightline, request or download:
Read the Data Protection Policy Request the trust pack
Sightline is hosted on Cloudflare — encrypted and region-configurable, with data residency available for international customers. Questions? Get in touch.
This statement reflects our posture as of 2026-06-07 and is updated as our program matures. It describes alignment and, where stated, self-attestation; externally-audited certifications are labeled “on roadmap” until earned. It is provided for transparency and is not a warranty.
Request our DPA, security whitepaper, or latest self-assessment — generated by Sightline, of Sightline.