Trust at Pivot

See how Pivot protects customer data, supports privacy and compliance requirements, and gives your team the evidence it needs to move through security reviews.

Security & compliance

A clearer path through every trust review

Pivot brings its security controls, privacy commitments, compliance resources, and operational practices into one public view—so legal, IT, and procurement teams can evaluate the platform with less back-and-forth.

Data Security

Data encryption

All data to and from Pivot is encrypted in transit (TLS 1.2/1.3) and at rest (AES-256). Encryption keys are managed in cloud KMS with strict access controls and audit trails.

Infrastructure security

Pivot runs on hardened cloud infrastructure (AWS) with Cloudflare at the edge for DDoS protection and performance. Networks are segmented, access is tightly controlled, and environments are continuously monitored.

Open, transparent development

Pivot is developed in public under a Business Source License (BSL), which invites scrutiny of our codebase and accelerates fixes for security issues across app and dependencies.

Data residency (via Private Cloud)

For organizations with residency requirements (including EU), Pivot offers Private Cloud deployment with dedicated, region-scoped infrastructure. See /security/data-residency for options and regional coverage.

System Security

Secrets management

Centralized secrets management, regular rotation, and least-privilege access reduce the exposure of credentials and sensitive configuration.

Single sign-on (SSO)

SSO (including SAML) is available for enterprise customers and used internally, helping reduce password risk and centralize access control.

Supply chain security

Automated dependency scanning, vendor due diligence, and monitored build pipelines help defend against supply-chain attacks and accidental exfiltration.

Pen testing

Independent third parties conduct annual penetration tests across app, API, and cloud layers. Findings are triaged to remediation under documented SLAs.

Report a vulnerability

We welcome good-faith security research and provide safe harbor under our disclosure policy.

Pivot Security Culture
Compliance and assurance

Pivot supports customers navigating GDPR, UK GDPR, Swiss FADP, CCPA/CPRA, LGPD, and HIPAA-eligible workflows. Our program combines public legal commitments, contractual safeguards, documented technical controls, and annual independent penetration testing, with additional review materials available to enterprise customers under NDA.

Incident response and recovery

We have a comprehensive incident response plan and real-time system monitoring to quickly address any security concerns. Our team of dedicated engineers is on-call 24/7 to detect, respond to, and mitigate potential security incidents. Additionally, our robust multi-cloud backup and recovery protocols ensure your data remains protected in the event of an incident.

Continuous improvement

Our security practices are constantly evolving to meet the challenges of operating a global cloud service that supports web, desktop, and mobile applications. We collaborate with industry experts and adopt the latest security best practices to provide a secure and dependable collaboration environment.

Compliance & Privacy

GDPR / UK GDPR / Swiss FADP

Covered by our Data Processing Addendum (DPA), Technical and Organizational Measures, and

GDPR Compliance Statement.

CCPA / CPRA

We do not sell personal data and we honor access, deletion, and opt-out requests, as described in our

CCPA / LGPD / Privacy Frameworks Statement.

LGPD

Rights for Brazilian data subjects are supported through our controller/processor model and documented in the same

Privacy Frameworks Statement.

International data transfers

Pivot currently supports cross-border transfers with EU SCCs, the UK Addendum, Swiss adaptations, and supplementary measures detailed in our

Data Privacy Framework Statement.

Talk to our trust team

Ask about security reviews, privacy requests, agreements, or product support. Enterprise customers may request recent penetration-test summaries under NDA.

Create your own Knowledge Base

Experience the power of synchronized collaboration

Collaborate globally, instantly, together

Bring versatility to your course design

Blend community with content and learning

Unite internal and external teams

Consolidate wikis, projects, and messaging

Try dynamic multi-modal collaboration