SOC 2 Type II
Independent control examination
CISO-led program
Executive oversight and accountability
Risk-based safeguards
Administrative, technical, and operational
Continuous improvement
Review, testing, and remediation
Trust is earned in layers
Remi's Information Security and Privacy Program is built around confidentiality, integrity, and availability. It combines governance, people, processes, and technology—and evolves as our business, services, risks, and obligations change.
Governance & accountability
A CISO-led program, executive oversight, clear ownership, policies, training, and periodic reporting keep security and privacy connected to business decisions.
Identity & access
Access is approved for a business need, limited by least privilege, protected with strong authentication, reviewed periodically, and removed when no longer required.
Data protection & privacy
Administrative, technical, and operational safeguards support secure transmission, protected storage, appropriate retention, and secure disposal across the information lifecycle.
Secure engineering
Security and privacy are considered during design, development, testing, change approval, and production operations—not added only after a feature is built.
Monitoring & response
Logging, monitoring, escalation, and incident response processes help us identify, investigate, contain, recover from, and learn from security or privacy events.
Resilience & third parties
Continuity and recovery planning, backup practices, vendor due diligence, contractual safeguards, and ongoing review extend protection beyond our own teams and systems.
How we operate
A program that adapts to new risks
Security is an ongoing discipline. We use a repeatable cycle to reduce risk, detect issues, and respond effectively in addition to strengthening controls over time.
01
Prevent
Risk assessment, policies, secure design, access controls, workforce training, hardening, and vendor governance reduce avoidable exposure.
02
Detect & respond
Monitoring, reporting channels, incident procedures, escalation, and recovery coordination support timely action when something needs attention.
03
Assure & improve
Audits, testing, access reviews, exercises, lessons learned, and remediation tracking help keep the program effective as conditions change.
Privacy with purpose
Privacy is a priority, not an afterthought
Remi's privacy program is governed alongside security. We assess privacy risk, train our workforce, protect personal information with appropriate safeguards, and maintain processes for incident response and required notifications.
Purpose-aware handling
Information is handled to support defined services, business activities, and legal or contractual responsibilities.
Authorized access
Personal information is limited to people and systems with an approved need.
Lifecycle protection
Retention, return, deletion, and disposal practices are governed by policy and applicable obligations.
Review & accountability
Training, policy review, incident procedures, and executive oversight reinforce responsible handling.
Independent assurance
Independent assurance for customers and partners
Remi has completed a SOC 2 Type II examination covering controls relevant to Security, Confidentiality, and Availability. Qualified customers and partners can request the report and other assurance materials through our Vanta Trust Center.

Common questions
A clearer path to assurance
Start here for high-level answers, then use our Trust Center for controlled access to supporting materials.
Questions about security or privacy?
Our teams are available to support customer assurance, privacy questions, and reports of suspected security concerns.
