Security Trust Center

Inspire Software is built to meet the security, compliance, and data handling requirements of mid-market and enterprise HR and IT teams. This page covers our compliance posture, data handling practices, access controls, encryption, and how to request detailed security documentation.

Last updated: February 2026Reviewed by: Inspire Security Team

What is Inspire's compliance posture?

🔐SOC 2 Type II
In progress

Our security program is designed around SOC 2 Trust Service Criteria. Full certification documentation available to enterprise prospects under NDA.

🇪🇺GDPR
Supported

Data subject rights, DPAs, subprocessor transparency, and right to deletion are all supported. DPAs available on request.

🇺🇸CCPA
Supported

California Consumer Privacy Act requirements are addressed in our privacy practices. See our Privacy Policy for details.

🏢US Data Residency
Standard

All primary data is hosted in US-based AWS infrastructure. Enterprise customers may request additional data residency configurations.

🔑SSO (SAML 2.0)
Included

Supported with Okta, Azure AD / Entra ID, Google Workspace, OneLogin, and other SAML 2.0 compatible identity providers.

⚙️SCIM 2.0
Included

Automated user provisioning and deprovisioning via SCIM 2.0. Employees are added and removed based on your identity provider.

How does Inspire handle and protect customer data?

Data you control

You own your data. Inspire processes it on your behalf as a data processor. You can export all your data at any time. Upon contract termination, data is deleted according to your agreed retention schedule.

Employee PII handling

Employee names, emails, and work-related performance data are stored. We do not collect sensitive personal information (SSN, financial data, health records) as part of normal platform operations. See our AI Trust page for AI-specific data handling.

Data isolation

Customer data is logically isolated. One customer's data is never accessible to another customer. Multi-tenant architecture includes strict access controls at the application and database layers.

Backup and recovery

Data is backed up daily with point-in-time recovery available. Backup data is encrypted and stored in geographically separate locations. Recovery time objectives (RTOs) and recovery point objectives (RPOs) are documented in enterprise SLAs.

Incident response

We maintain an incident response plan. In the event of a security incident affecting customer data, we notify affected customers within 72 hours of confirmation — consistent with GDPR Article 33 requirements.

What access controls does Inspire provide?

ControlDetails
SSO (SAML 2.0)Supported. Okta, Azure AD, Google, OneLogin. No extra cost.
SCIM 2.0Automated user provisioning/deprovisioning from your IdP.
Role-based access controlAdmin, Manager, Employee, and custom roles with configurable permissions.
MFAMulti-factor authentication supported via your SSO identity provider.
IP allowlistingAvailable for enterprise customers — restrict access to approved network ranges.
Audit loggingAdmin-level audit logs of user actions, configuration changes, and data exports.
Session managementSession timeouts, concurrent session limits, and forced re-authentication configurable.

How is data encrypted?

🔐
In transit
TLS 1.2+ for all data in transit. HTTPS enforced on all endpoints.
🗄️
At rest
AES-256 encryption for all data stored at rest, including database backups.
🔑
Key management
Encryption keys managed via cloud provider KMS (AWS Key Management Service).
📦
Backups
Database backups encrypted and stored in geographically separate regions.

What subprocessors does Inspire use?

Inspire uses a limited set of trusted subprocessors to deliver our platform services. Our full subprocessor list is available upon request. We notify customers of material changes to our subprocessors as required by our DPA.

Key subprocessor categories include: cloud infrastructure (hosting, storage, compute), email delivery, customer support tooling, and analytics infrastructure. We do not sell data to subprocessors or third parties.

Request Full Subprocessor List →

Need security documentation?

Enterprise and IT teams can request our security overview, completed VSAQ/SIG questionnaire, penetration test executive summary, and DPA — available under NDA to qualified prospects.

Security FAQs

Is Inspire SOC 2 Type II certified?
Inspire is actively pursuing SOC 2 Type II certification. Our security program is designed around SOC 2 Trust Service Criteria. Detailed compliance documentation is available to enterprise prospects upon request under NDA.
 
Where is Inspire's data hosted?
Inspire’s platform is hosted in US-based cloud infrastructure (AWS). Data residency options and additional regional configurations are available for enterprise customers with specific requirements. Contact us to discuss your requirements.
 
Does Inspire support GDPR compliance?
Yes. Inspire supports GDPR requirements including data subject access requests, right to deletion, data portability, and Data Processing Agreements (DPAs). DPAs are available upon request. We maintain subprocessor lists and notify customers of material changes.
 
Does Inspire support SSO?
Yes. Inspire supports SAML 2.0-based SSO with major identity providers including Okta, Azure AD (Entra ID), Google Workspace, and OneLogin. SSO is included in all plans at no additional cost.
 
 
Does Inspire support SCIM for user provisioning?
Yes. SCIM 2.0 is supported for automated user provisioning and deprovisioning. This ensures employees are added and removed from Inspire automatically based on your identity provider — critical for offboarding compliance.
 
 
 
How is data encrypted?
Data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption. Database backups are encrypted. Encryption key management follows cloud provider best practices.
 
 
 
 
How can we request a security review or penetration test results?
Enterprise prospects can request security documentation including our security questionnaire responses, penetration test executive summaries, and compliance overview under NDA. Use the ‘Request Security Docs’ button on this page or contact your account team.
 
 
 
 
 
Does Inspire have a bug bounty program?
We have a responsible disclosure policy in place. Security researchers who discover vulnerabilities can report them to security@inspiresoftware.com. We acknowledge reports within 2 business days and follow coordinated disclosure practices.