Skip to content

Trust and compliance

Potloc’s certifications, audit reports, policies and security documentation live in one place:

trust.potloc.com

Start there for a security review, a questionnaire, a copy of a report, or the list of sub-processors. None of it is repeated here.

This site and the trust centre answer different questions, and a fact lives on only one of them:

Question Where
Which certifications does Potloc hold, and against which framework? trust.potloc.com
Which policies govern Potloc’s people, systems and vendors? trust.potloc.com
Where is data hosted, and who are the sub-processors? trust.potloc.com
How do I request a report or answer a security questionnaire? trust.potloc.com
How does sign-in work, and what can my organisation enforce? Signing in, SSO
What does the platform hold about me and my respondents? Privacy and data handling
What is specific to reaching Potloc over MCP? MCP security and compliance

The rule behind the split: the trust centre says how Potloc is run and audited; this site says how the product behaves. A certification, a policy or a hosting fact is renewed on a schedule and belongs on the trust centre, so the docs site never carries a stale copy. A behaviour of the product (what a role unlocks, what an export contains, how a session ends) changes with a release and belongs here.

Asking a question the trust centre does not answer

Section titled “Asking a question the trust centre does not answer”

Write to support@potloc.com. Architecture questions, a compliance requirement specific to your engagement, and anything you believe is a security issue all go to the same address.