How we protect your organization's data
Whalemate processes names, emails and simulation results of your employees. Where that data lives, who accesses it and under which controls. We only show what is certified today: ISO/IEC 27001:2022.
Platform controls
Encryption
TLS 1.3 in transit and AES-256 at rest.
Access
SSO for the internal team, 2FA and least privilege.
Traceability
Access and change logging.
Continuity
Availability and recovery controls.
Residency
Hosting according to the scope agreed with the customer.
Retention
Retention and deletion policy defined in the DPA.
What we collect and why
No individual metric is used for disciplinary purposes. That's in the contract, not only on this page.
| Data | Why | Who sees it | Retention |
|---|---|---|---|
| Name and work email | Send the simulation and assign training | Program administrator | For the life of the contract |
| Simulation result | Compute the index and trigger reinforcement | Program administrator | 24 months |
| Training progress | Compliance evidence | Administrator and audit | 24 months |
| Area and role | Calibrate the scenario by profile | Aggregated, not individual | For the life of the contract |
Subprocessors
If you found a vulnerability, write to security@whalemate.com. We respond within 48 business hours. We do not take legal action against good-faith research.
Infrastructure on AWS. Transactional email and product analytics per the current DPA. The full list is updated with prior notice.
Program capabilities
2FA, session and brute-force
Whoever administers does not get in on a password alone. 2FA, session time, and brute-force lockout sit in the console, next to roles and the audit log.
Users, roles and permissions
Who enters the console. Not roster SSO: operator access, with least privilege.
Audit log
Admin changes: who touched a permission, when. Course-completion logs also live on compliance.
How we handle names, emails, and simulation results
Whalemate processes roster data to run the program. This page declares what is certified today: ISO/IEC 27001:2022. We do not invent SOC 2 or other badges. The DPA is the document that governs processing.
A human-risk program does not work without a roster. That means names, work emails, area, role when it exists, simulation results, and training progress. Those data live to send the exercise, assign reinforcement, and produce evidence. They do not live for a disciplinary file. The Trust Center says what is collected, why, who sees it, and with what retention. The contract and the DPA repeat the use limit. If a customer wants the score for a proceeding, they are asking for something this platform does not offer.
The certification we show is ISO/IEC 27001:2022. The badge is on the site because it is current. We do not list SOC 2, ISO 27701, or other frameworks as ours. Platform controls — encryption in transit and at rest, internal SSO, 2FA, least privilege, access logs, continuity, agreed residency — are described on this page. Residency and subprocessors are closed in the DPA. Infrastructure on AWS. The subprocessor list is updated with notice. Responsible disclosure: security@whalemate.com.
The DPA is the document legal and procurement should ask for, not a marketing paragraph. It defines processing, controller instructions, subprocessors, and retention. The Trust Center does not replace it: it makes it findable. If there is a question the DPA does not cover, it is answered at the security table — not with a new claim on a banner. We want this page to be link-worthy from a tender. That is why we do not fill it with badges we do not have.
Certification, data, and permitted use
If one of the three is invented, the Trust Center stops being useful to legal.
ISO/IEC 27001:2022
It is the only certification we declare. The badge visible on the site matches that scope. We do not use the standard as decoration or mix it with your organization’s certification. If a…
What data we process
Name and work email to send and assign. Simulation result for the index and reinforcement. Training progress for evidence. Area and role to calibrate, aggregated when that applies. We do not ask for…
Non-disciplinary use
No individual metric is used to punish. It is in the Trust Center and the contract, not only in a brand value. The program administrator sees the detail. The executive report aggregates. Legal can…
Trust Center questions
Do you have SOC 2 or other certifications besides ISO?
Where do I read the DPA?
Can you use our simulation results for marketing?
Who at Whalemate sees the roster?
How do I report a vulnerability?
Want to review scope with the team?
The Trust Center covers what is certified today. Concrete scope is closed in the demo.