Security at Culture Amp
Learn about our security and data protection measures as well as our compliance & regulatory certifications at our Security & Privacy Trust Centre
Compliance certifications, standards, and regulations

SOC2 Type II
The SOC2 Type II report provides assurance to our customers and partners that Culture Amp uses secure systems and processes to safeguard their data.

ISO/IEC 27001:2013
Culture Amp is certified as compliant with ISO/IEC 27001:2013 which is globally recognized as the premier information security management system (ISMS) standard.

General Data Protection Regulation (GDPR)
Culture Amp is GDPR compliant, handling all personal data in compliance with the latest EU laws.

California Consumer Privacy Act (CCPA)
Culture Amp is compliant with the California Consumer Privacy Act (CCPA).

Brazilian General Data Protection Law (LGPD)
Culture Amp is compliant with the Brazilian General Data Protection Law (LGPD).
Frequently asked questions
Where is data stored?
All production systems are hosted in Amazon's AWS cloud platform. Data is stored in AWS US (Oregon) and backed up in AWS US (Virginia). For customers located in Europe, data is stored in AWS EU (Ireland) and backed up in AWS EU (Frankfurt).
What private information do you require to provide your service?
Culture Amp requests a full name and email address for basic functionality.
Customers often choose to include demographics within the platform such as job title, department, gender, and tenure.
Do you use third parties to deliver your product?
Yes, please see our list of sub-processors here.
We are committed to ensuring the security of our information, systems, and services
If you believe you have found a vulnerability, please share your findings with our security team:
security@cultureamp.com
For the protection of our customers, we ask that you do not publicly disclose, discuss or confirm the details of any suspected security issues.