How we protect your organization's data

Whalemate processes names, emails and simulation results of your employees. Where that data lives, who accesses it and under which controls. We only show what is certified today: ISO/IEC 27001:2022.

Architecture

Platform controls

Encryption

TLS 1.3 in transit and AES-256 at rest.

Access

SSO for the internal team, 2FA and least privilege.

Traceability

Access and change logging.

Continuity

Availability and recovery controls.

Residency

Hosting according to the scope agreed with the customer.

Retention

Retention and deletion policy defined in the DPA.

Employee data

What we collect and why

No individual metric is used for disciplinary purposes. That's in the contract, not only on this page.

DataWhyWho sees itRetention
Name and work emailSend the simulation and assign trainingProgram administratorFor the life of the contract
Simulation resultCompute the index and trigger reinforcementProgram administrator24 months
Training progressCompliance evidenceAdministrator and audit24 months
Area and roleCalibrate the scenario by profileAggregated, not individualFor the life of the contract
Responsible disclosure

Subprocessors

If you found a vulnerability, write to security@whalemate.com. We respond within 48 business hours. We do not take legal action against good-faith research.

Infrastructure on AWS. Transactional email and product analytics per the current DPA. The full list is updated with prior notice.

In this module

Program capabilities

Access

2FA, session and brute-force

Whoever administers does not get in on a password alone. 2FA, session time, and brute-force lockout sit in the console, next to roles and the audit log.

Permissions

Users, roles and permissions

Who enters the console. Not roster SSO: operator access, with least privilege.

Trails

Audit log

Admin changes: who touched a permission, when. Course-completion logs also live on compliance.

Trust Center

How we handle names, emails, and simulation results

Whalemate processes roster data to run the program. This page declares what is certified today: ISO/IEC 27001:2022. We do not invent SOC 2 or other badges. The DPA is the document that governs processing.

A human-risk program does not work without a roster. That means names, work emails, area, role when it exists, simulation results, and training progress. Those data live to send the exercise, assign reinforcement, and produce evidence. They do not live for a disciplinary file. The Trust Center says what is collected, why, who sees it, and with what retention. The contract and the DPA repeat the use limit. If a customer wants the score for a proceeding, they are asking for something this platform does not offer.

The certification we show is ISO/IEC 27001:2022. The badge is on the site because it is current. We do not list SOC 2, ISO 27701, or other frameworks as ours. Platform controls — encryption in transit and at rest, internal SSO, 2FA, least privilege, access logs, continuity, agreed residency — are described on this page. Residency and subprocessors are closed in the DPA. Infrastructure on AWS. The subprocessor list is updated with notice. Responsible disclosure: security@whalemate.com.

The DPA is the document legal and procurement should ask for, not a marketing paragraph. It defines processing, controller instructions, subprocessors, and retention. The Trust Center does not replace it: it makes it findable. If there is a question the DPA does not cover, it is answered at the security table — not with a new claim on a banner. We want this page to be link-worthy from a tender. That is why we do not fill it with badges we do not have.

Three trust anchors

Certification, data, and permitted use

If one of the three is invented, the Trust Center stops being useful to legal.

ISO/IEC 27001:2022

It is the only certification we declare. The badge visible on the site matches that scope. We do not use the standard as decoration or mix it with your organization’s certification. If a…

What data we process

Name and work email to send and assign. Simulation result for the index and reinforcement. Training progress for evidence. Area and role to calibrate, aggregated when that applies. We do not ask for…

Non-disciplinary use

No individual metric is used to punish. It is in the Trust Center and the contract, not only in a brand value. The program administrator sees the detail. The executive report aggregates. Legal can…

Trust Center questions

Do you have SOC 2 or other certifications besides ISO?
The certification we declare is ISO/IEC 27001:2022. We do not list SOC 2 or other badges as ours. If a tender asks for them, the honest answer is that, plus the DPA and the controls on this page. Inventing an “in process” is not a shortcut we use.
Where do I read the DPA?
In the site’s legal hub, next to privacy, terms, and cookies. The Trust Center links to that document because it governs processing. If you need a negotiated version, that is discussed at the commercial and legal table. This page does not replace signing the DPA.
Can you use our simulation results for marketing?
Public reports do not expose a customer’s roster. A case study is published when the customer and the narrative are validated. We do not use your click rate in an ad. If a research report uses a sample, the method is in that PDF — not in a loose headline.
Who at Whalemate sees the roster?
Internal access follows least privilege and is logged. Customer success sees what is needed to operate the account. It is not open access for the whole team. Subprocessor and residency detail is in the DPA. Ask in the demo if your tender wants a named list.
How do I report a vulnerability?
Write to security@whalemate.com. We respond within 48 business hours. We do not start legal action against good-faith research. There is no bounty program published on this page: if a scope exists, it is communicated on that channel — a prize is not invented here.

Want to review scope with the team?

The Trust Center covers what is certified today. Concrete scope is closed in the demo.