We’re proud to meet the highest global standards for data security and compliance

Assessed against stringent AICPA Trust Criteria

Your privacy and data rights are safeguarded

Robust controls for information security management

AI-specific governance, built-in from the ground up
We’re proud to meet the highest global standards for data security and compliance

All data — at rest and in transit — is encrypted using industry-standard protocols (AES-256, TLS 1.2+). This ensures that data is always protected, even during processing or transfer.

All customer data is stored exclusively within regulatory-compliant geographies, with enforced controls for residency and sovereign cloud preferences, ensuring firms meet local legal obligations.

Our backend services operate entirely within private, secured networks. No compute resources are exposed to the public internet — only explicitly secured front-end interfaces are accessible externally.

We leverage Google Cloud’s Security Command Center for 24/7 real-time monitoring, vulnerability scanning, and alerting — proactively detecting anomalies, intrusions, and misconfigurations.

Each customer’s data is stored in a dedicated and logically isolated environment — ensuring no cross-tenant access, no shared databases, and complete customer-level segregation.

Access to all systems is governed by zero trust architecture principles, with enforced MFA, least-privilege roles, network-level policies, and endpoint hardening — across both cloud and internal devices.
With Palindrome, your firm’s sensitive data is:
Learn more about our compliance documentation and ongoing security practices.
With Palindrome, your firm’s sensitive data is:
Learn more about our compliance documentation and ongoing security practices.