Security & Procurement
Everything your procurement team needs to evaluate us
Security Checklist
Data Protection
Encryption at rest
AES-256 encryption for all stored data
Encryption in transit
TLS 1.3 for all API communications
Data residency controls
Client-specified region deployment available
Right to deletion
Complete data purge within 30 days of request
Access Control
Multi-factor authentication
Mandatory 2FA for all team members
Role-based access control
Principle of least privilege enforced
Access logs and audit trails
90-day retention of all access logs
Background checks
All team members undergo verification
Development Security
Secure SDLC
Security integrated at every phase
Code reviews
Mandatory peer review for all changes
Dependency scanning
Automated vulnerability scanning
Security testing
SAST/DAST in CI/CD pipeline
Compliance
SOC 2 Type II
Audit scheduled Q2 2024
GDPR compliance
Full compliance with EU regulations
CCPA compliance
California privacy rights supported
HIPAA capability
BAA available for healthcare clients
Key Policies
Certifications & Audits
Current
- ✓ISO 27001:2013 (Information Security)
- ✓GDPR Compliant
- ✓CCPA Compliant
In Progress
- ◐SOC 2 Type II (Q2 2024)
- ◐ISO 9001:2015 (Q3 2024)
Schedule a Procurement Call
Book a consultation with our team to discuss your procurement requirements, security questions, and get personalized answers to your evaluation process.
Free Consultation
No cost, no obligation - just expert procurement guidance
30-45 Minutes
Focused discussion on your specific requirements
Expert Team
Meet with our security and procurement specialists
Need Documents Instead?
We can provide specific documentation or answer detailed security questions during our call.
Contact Procurement TeamQuick Evaluation
Use our vendor scorecard tool to evaluate us against your requirements.
Evaluate DrexusWhy Procurement Teams Trust Us
Fortune 500 Ready
Successfully passed procurement reviews at 15+ enterprise companies
Security First
Zero security incidents in 8 years of operation
Transparent Process
Clear contracts, no hidden terms, flexible engagement models