SOC 2 program
Controls and evidence tracked against SOC 2 criteria; independent audit is the next milestone
HIPAA
Engagements delivered under signed Business Associate Agreements
Screened
Employees and contractors are screened before client-system access
Quarterly
Security attestations signed by every team member, with recurring security training through the year
Insured
Technology E&O, cyber, commercial crime, and general liability coverage in force
Security starts with who touches your data.
Screened before access
Employees and contractors are screened before being granted access to client systems or data. The standard background check covers criminal records across five years of residence history, with international checks where a team member has lived abroad, and terrorist watchlist screening.
Trained from day one
Every team member completes a defined security-awareness onboarding path before access is granted, then recurring training modules and simulated phishing exercises through the year on the KnowBe4 platform. HIPAA training is required before any access to protected health information, and FERPA training before any access to student education records.
Attested every quarter
Each team member signs a quarterly security attestation covering endpoint detection and response on every work computer, operating system currency, disk encryption, multi-factor authentication wherever available, unique passwords in a managed password vault, VPN use on untrusted networks, credential handling, and phishing vigilance.
Bound in writing
Every employment and contractor agreement carries confidentiality, data-handling, and intellectual property obligations that survive the engagement, plus return-of-property requirements on exit.
Secure by architecture, on every engagement
Our institutional systems run on AWS with security set at the architecture stage: role-based access control mapped to each client’s real organizational roles, managed authentication, least-privilege permissions, logging and alerting, and documented disaster recovery. A security and access-control design is a standard deliverable of every custom build. Methodology →
Standing practices on our own systems and client environments include:
Endpoint detection and response on every work computer
Critical vulnerabilities (CVSS 8.0 and above) patched within 14 days; all available patches applied within 30 days
Multi-factor authentication and managed, unique credentials across work platforms
Encryption in transit (TLS 1.2 or higher) and AES-256 encryption at rest on Watkyn-managed storage
Cloud backup of critical data
Access and ownership. Access to client systems is limited to assigned project personnel, managed through restricted credential storage, reviewed quarterly, and removed when the assignment ends. Repositories, documentation, and project assets are handed over to client ownership at completion, and any continuing Watkyn access requires the client’s explicit authorization.
We also right-size. We have advised government clients against costlier hosting and compliance tiers their data did not require. You get the controls your risk profile calls for, and a straight explanation of why.
We’ve worked under the rules you answer to.
HIPAA, delivered under BAA
We’ve built and operated systems governed by HIPAA under signed Business Associate Agreements, including COVID-19 case management and vaccination tracking for Saint Louis University. Team members complete HIPAA training before any access to protected health information, and on those engagements we require Business Associate Agreements of our subcontractors before access is granted, preserving the full chain of responsibility the law is designed to create.
FERPA and student data
Our higher education work is delivered under FERPA’s school-official framework: team members complete FERPA training before any access to student education records, education records are never used to train AI models, and we are prepared to sign an institution’s own FERPA addendum where required.
State and program-specific requirements
From public-records obligations to state data privacy law to program reporting rules, each engagement’s regulatory environment is a requirements source from day one, documented in discovery and carried through the security design.
The coverage behind the commitments
Watkyn carries the insurance program an institutional engagement calls for. Current coverage includes technology errors & omissions ($1,000,000 per claim), cyber liability spanning breach response, forensics, notification, regulatory proceedings, cyber extortion, business interruption, and data recovery ($2,000,000), commercial crime including employee theft of client property ($1,000,000), and commercial general liability ($2,000,000 per occurrence / $4,000,000 aggregate).
Certificates of insurance are available on request and govern all terms, limits, exclusions, and endorsements.
One standard, all the way down
Subcontractors
Subcontractors sign the same confidentiality and data-handling obligations as employees, pass the same screening, and complete the same security attestations. Where an engagement involves protected health information, subcontractors execute Business Associate Agreements before any access is granted.
Third-party vendors
The platforms we use in client delivery are reviewed under our vendor risk management process before use and at least annually, and maintained in a vendor inventory. New tools that would process client data require approval before they enter a client environment. Under our standard Data Processing Addendum, the sub-processors supporting an engagement are disclosed to the client, with notice before material changes.
Documents available to evaluators
Certificate of insurance (on request)
W-9 and company information (on request)
Ethics & Conduct Summary →
the full Code of Ethics on request during vendor review
Written security policies, including Information Security, Acceptable Use, and Incident Response (under NDA)
Standard Data Processing Addendum and, for HIPAA engagements, Business Associate Agreement terms (on request)
Security questionnaire responses, in your required format
NAICS: 541511, 541512, 541519, 513210; see the full procurement facts on our Government page →
Common questions about our security program
Not yet. Our security program is built and operated against SOC 2 criteria, with controls and evidence tracked continuously, and an independent audit is the next milestone. This page states our exact status and is updated as milestones land.
Yes. We have delivered HIPAA-governed systems under signed BAAs, our team members complete HIPAA training before any access to protected health information, and we require BAAs of subcontractors on those engagements.
Only team members assigned to your project, under least-privilege access, screening, signed confidentiality obligations, and quarterly security attestations. Access is removed when the engagement or the assignment ends.
Yes, under written rules. Our developers use approved AI tools to plan builds and accelerate delivery, and an expert designs, reviews, and stands behind every system we deliver. We do not use client data to train AI models, and we use AI tools and settings designed to prevent submitted client data from being used for model training. Regulated data is gated harder: no protected health information, education records, government-issued identifiers, or financial account data enters any AI tool unless the statement of work authorizes it, the client approves in writing, and the tool is covered by the appropriate data-protection instrument.
Yes. We respond to questionnaires, vendor reviews, and RFP security sections in your required format, and can provide our written policies under NDA.
Our Incident Response Policy governs the sequence: we investigate promptly, contain the issue, preserve evidence, notify affected clients according to contractual and legal obligations, coordinate with counsel and insurers where appropriate, and document corrective action. Under our standard Data Processing Addendum we notify affected clients without undue delay after becoming aware of an incident, and notification commitments are set per engagement to match your requirements.
Sometimes. When your data or your regulator requires it, we build for it. When it is unnecessary, we say so, because oversized infrastructure wastes public money. The answer comes out of discovery, documented and justified.
Put our security program in front of your evaluators.
Send us your questionnaire, vendor-review packet, or RFP security section. We’ll respond in your format, with evidence.
Questions, or something specific you’re weighing? We’re happy to talk: 201-644-5251.