Trust at Pivot
See how Pivot protects customer data, supports privacy and compliance requirements, and gives your team the evidence it needs to move through security reviews.
Security & compliance
A clearer path through every trust review
Pivot brings its security controls, privacy commitments, compliance resources, and operational practices into one public view—so legal, IT, and procurement teams can evaluate the platform with less back-and-forth.
Regulatory
GDPR, UK GDPR & FADP
DPA, transfer safeguards, and public privacy commitments
Privacy rights
CCPA, CPRA & LGPD
Access, deletion, opt-out, and regional rights support
Healthcare
HIPAA-ready with a BAA
Eligible use with the right agreement and configuration
Assurance
Independent security testing
Annual penetration testing and documented remediation
Data encryption
All data to and from Pivot is encrypted in transit (TLS 1.2/1.3) and at rest (AES-256). Encryption keys are managed in cloud KMS with strict access controls and audit trails.
Infrastructure security
Pivot runs on hardened cloud infrastructure (AWS) with Cloudflare at the edge for DDoS protection and performance. Networks are segmented, access is tightly controlled, and environments are continuously monitored.
Open, transparent development
Pivot is developed in public under a Business Source License (BSL), which invites scrutiny of our codebase and accelerates fixes for security issues across app and dependencies.
Data residency (via Private Cloud)
For organizations with residency requirements (including EU), Pivot offers Private Cloud deployment with dedicated, region-scoped infrastructure. See /security/data-residency for options and regional coverage.
Secrets management
Centralized secrets management, regular rotation, and least-privilege access reduce the exposure of credentials and sensitive configuration.
Single sign-on (SSO)
SSO (including SAML) is available for enterprise customers and used internally, helping reduce password risk and centralize access control.
Supply chain security
Automated dependency scanning, vendor due diligence, and monitored build pipelines help defend against supply-chain attacks and accidental exfiltration.
Compliance and assurance
Pivot supports customers navigating GDPR, UK GDPR, Swiss FADP, CCPA/CPRA, LGPD, and HIPAA-eligible workflows. Our program combines public legal commitments, contractual safeguards, documented technical controls, and annual independent penetration testing, with additional review materials available to enterprise customers under NDA.
Incident response and recovery
We have a comprehensive incident response plan and real-time system monitoring to quickly address any security concerns. Our team of dedicated engineers is on-call 24/7 to detect, respond to, and mitigate potential security incidents. Additionally, our robust multi-cloud backup and recovery protocols ensure your data remains protected in the event of an incident.
Continuous improvement
Our security practices are constantly evolving to meet the challenges of operating a global cloud service that supports web, desktop, and mobile applications. We collaborate with industry experts and adopt the latest security best practices to provide a secure and dependable collaboration environment.
Talk to our trust team
Ask about security reviews, privacy requests, agreements, or product support. Enterprise customers may request recent penetration-test summaries under NDA.
Create your own Knowledge Base
Experience the power of synchronized collaboration
Collaborate globally, instantly, together
Bring versatility to your course design
Blend community with content and learning
Unite internal and external teams
Consolidate wikis, projects, and messaging
Try dynamic multi-modal collaboration