New2026 IT Identity Trends Report is live.Download today →
Trust Center
Everything you need to evaluate ICI TECH's security posture — certifications, architecture, sub-processors, and our incident response approach.
Six pillars of our security program.
TLS 1.2+ in transit for every request. AES-256 at rest. Key management with HSM-backed envelope encryption.
Every internal access to customer data is just-in-time, approved, audited, and time-bound. Hardware key MFA required.
Tenant data is logically isolated at every layer — directory, audit log, queues, and storage.
Behavioral anomaly detection, drift alerts on production changes, and a 24/7 on-call SOC.
Documented runbooks, customer notification SLAs in the DPA, and post-mortems published to customers within 30 days.
Active-active across multiple AWS regions; RPO < 1 minute, RTO < 15 minutes for the core directory.
All audits are conducted annually by independent third parties.
Annual audit by an independent firm covering security, availability, and confidentiality.
Information security management system, audited against the ISO/IEC 27001:2022 standard.
Cloud-specific controls layered on top of ISO 27001.
Personal data protection in cloud environments.
Business Associate Agreement available for healthcare customers.
Healthcare-focused security and privacy framework, certified annually.
Data Processing Agreement available; EU/UK-specific contractual addenda included.
Privacy controls and data subject rights for California residents.
Service provider compliance for customers processing payment card data via ICI TECH.
Service providers we use to deliver ICI TECH. We notify customers 30 days before adding any new sub-processor.
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Compute, storage, networking | Global |
| Cloudflare | DDoS mitigation, edge delivery | Global |
| Datadog | Application telemetry & alerting | US / EU |
| Stripe | Billing & payment processing | US |
| Resend | Transactional email delivery | US / EU |
| Sentry | Error tracking | US / EU |
| Vercel | Marketing site hosting | Global edge |
| Anthropic | Aria AI assistant (no customer data trained on) | US |
To subscribe to sub-processor change notifications, email security@icitech.example.
Responsible disclosure
We pay bounties and credit researchers publicly. Initial response within 24 hours; coordinated disclosure timelines on every report.

Talk to our team about identity, access, and device management built for your workforce.