Security Overview

How we protect your data, and how to verify it.

Universities, national labs, hospitals, and research nonprofits trust FirstIgnite with sensitive information, including unpublished research, industry and donor relationships, and personal data. This page describes how we protect that information, what independent auditors have verified, and where to find the documentation your security team will need. Last updated September 2026.

Certifications and independent assurance

Independent auditors review our security program every year. The resulting certificates, reports, and evidence are available on our Trust Center at trust.firstignite.com.

ISO/IEC 27001:2022

FirstIgnite is certified to ISO/IEC 27001:2022. An accredited auditor reviews our information security management system annually to maintain the certification, and our 2026 surveillance audit found no nonconformities. The certificate is available on the Trust Center.

SOC 2 Type II

Our SOC 2 Type II examination covers the Security and Privacy Trust Services Criteria and is in its final stage. Once the auditor issues the report, we will make it available to current and prospective customers under NDA through the Trust Center.

Penetration testing

An independent security firm performs a penetration test of the FirstIgnite platform at least once a year, in addition to the vulnerability scanning we run internally. The most recent test was completed in early 2026, and we have remediated all findings. A summary letter is available on the Trust Center.

HECVAT

A completed HECVAT Full is available on the Trust Center so higher education security teams can review our controls in the format they already use.

Trust Center

The Trust Center holds our certificates, policies, and audit evidence, along with a request form for documents we share under NDA. You can also submit questions to our security team there. Our controls are monitored continuously through a compliance automation platform, so the evidence on the Trust Center reflects our current state rather than a snapshot from the last audit.

Visit the FirstIgnite Trust Center

Privacy and data protection

FirstIgnite follows GDPR principles across the platform, and our privacy practices were part of the SOC 2 Type II examination.

For personal data leaving Europe, we are self-certified under the EU-U.S. Data Privacy Framework, along with the UK Extension and the Swiss-U.S. Data Privacy Framework. Prighter is our Article 27 representative in the EU and UK, as our Privacy Policy notes.

A Data Processing Agreement is available to every customer, and we publish our subprocessors with the purpose, data categories, and location for each. Customers who need their data to remain in Europe can be hosted in our EU production environment. When a customer requests deletion, we follow a documented process that confirms the data has been removed from production systems and backups.

View our subprocessors

Access control and identity

For your users

Users sign in to FirstIgnite through single sign-on, including with their institution's identity provider. Administrators manage roles and permissions for their team and control who has access to what.

For our team

Every FirstIgnite employee and contractor signs a confidentiality agreement before receiving access and completes security awareness training on joining and annually thereafter. Production access follows least privilege and requires multi-factor authentication. We review access on a regular schedule and revoke it promptly when someone leaves.

Secure development

Every change to the platform goes through peer code review and automated testing before deployment, and development, staging, and production are separate environments. We scan dependencies and infrastructure for known vulnerabilities, patch on a schedule set by severity, and follow OWASP guidance throughout the development lifecycle. Our ISO 27001 and SOC 2 auditors review our change management process each year.

Infrastructure and encryption

Production runs primarily on Google Cloud Platform in the United States, with a second production environment in the European Union. Amazon Web Services supports storage, backups, and disaster recovery, and Microsoft Azure supports AI services and vector search. Each provider maintains its own compliance program, and the full list is on our subprocessors page.

Production environments are logically isolated in private networks, with access limited to authorized staff. Data in transit is protected with TLS 1.2 or higher, and HTTPS is required on every request. Data at rest is encrypted with AES-256. Backups are automated, encrypted, and tested regularly to confirm they can be restored.

AI and your data

AI is central to the FirstIgnite platform, and we are deliberate about how it handles customer data.

We do not train AI models on your data, and our model providers are not permitted to either. They process requests under enterprise and API terms that prohibit training on customer inputs and outputs.

Your prompts, documents, and platform data are used only to deliver the service to you. We do not sell them or share them beyond the subprocessors we disclose, and every AI provider we use appears on that list so you know which models may process your requests.

Monitoring, incident response, and continuity

We log and monitor production systems for security events and anomalous activity, with alerts routed to our on-call engineers. Our incident response plan is documented and tested at least annually. If an incident affects your data, we notify you within the timeframes in your agreement and work with you until it is resolved. Business continuity and disaster recovery plans are documented and tested on the same basis, with defined recovery objectives.

Vendor risk management

We assess every vendor with access to customer data before onboarding and review them on a recurring basis. That review covers their security certifications, data handling practices, and contractual commitments, and we put a data processing agreement in place where one is required.

Security governance

Security is owned at the executive level. Our CTO also serves as Chief Information Security Officer and leads the program, and a compliance automation platform monitors our controls continuously. Policies are reviewed and approved annually.

Have a question or need documentation?

Visit the Trust Center to review our ISO 27001 certificate, penetration test summary, HECVAT, and policies. The SOC 2 Type II report will be available there once it is issued.

Go to trust.firstignite.com

If you would prefer to speak with someone directly, send us a note and we will connect you with our security team.

Send us a note