TRUST CENTER

Clear practices, honest boundaries

Review how YourAgencyDesk protects agency workspaces, uses service providers, responds to security events, supports recovery, and presents sourced regulatory information.

Current controls documented
Assurance status. These pages describe controls and operating practices currently represented by YourAgencyDesk. They do not claim SOC 2, ISO 27001, HIPAA certification, a penetration test, or another independent audit that has not been completed.

Security overview

YourAgencyDesk uses HTTPS, authenticated application access, role- and agency-scoped database policies, private file storage, defensive browser headers, rate-limited server functions, and Stripe-hosted payment collection. Authenticator-app MFA is available for customer accounts. Read the security overview for additional detail.

Data retention and deletion

Active customer data

Workspace records are retained while needed to provide the service and follow the agency's instructions. Authorized users can update or remove supported operational records from the application.

Account closure

Customers should request an export before closure. Following a verified closure or deletion request, data is removed from active systems subject to security, fraud-prevention, contractual, legal, and accounting requirements.

Backups and logs

Deleted information may remain temporarily in provider-managed backups, security logs, or recovery systems until those copies age out through applicable provider processes.

Billing and support

Billing records may be retained by Stripe and as required for financial reporting. Support and security communications are kept only as needed to resolve the matter and maintain appropriate business records.

No fixed deletion or backup-expiration interval is promised on this page. Contractual commitments, where applicable, are stated in the customer's agreement.

Service providers and subprocessors

YourAgencyDesk relies on specialized providers to operate the service. The current list, purpose, and data categories are maintained on the Subprocessor List. Customers should review that page for changes.

Incident response

Suspected incidents are triaged to determine scope and impact, contain affected access, preserve relevant evidence, remediate the cause, and restore safe operation. When an incident affects customer information, YourAgencyDesk will provide notices required by applicable law and binding customer agreements. We do not publish an untested universal notification deadline.

Report a suspected incident through the responsible disclosure process. Do not include client records, credentials, or exploit data in the first message.

Backup and disaster recovery

The service uses managed cloud infrastructure and provider recovery capabilities. Recovery procedures prioritize authentication, agency data access, private files, and billing continuity. Backup availability and restoration procedures are reviewed as the platform evolves.

No untested recovery guarantee. YourAgencyDesk does not currently publish a guaranteed recovery-point objective (RPO) or recovery-time objective (RTO). Any future target will be published only after it is documented, tested, and supportable by the underlying provider commitments.

Responsible vulnerability disclosure

Security researchers and customers can review the disclosure policy and machine-readable security.txt. YourAgencyDesk does not currently operate a paid bug-bounty program.

Regulatory-alert methodology

Regulatory alerts use automated web-assisted discovery to surface potentially relevant changes. AI may summarize a source; it does not create the underlying requirement. Each live result is expected to include its originating organization, direct source link, relevant dates, jurisdiction, product line, last-checked time, and review status.

Automated discovery is not legal advice or a determination of applicability. High-impact items must be human reviewed before YourAgencyDesk marks them ready for customer notification. Read the complete Regulatory Alert Methodology or report a possible error.

Privacy requests and account deletion

Requests for access, correction, deletion, portability, or account closure begin on the Data Rights page. For records controlled by an agency customer, YourAgencyDesk may refer the request to that agency or assist it in responding. Identity and authority are verified before account-level action is taken.

Last updated: August 27, 2026