Yes. Eternal Pro is SOC 2 Type 2 certified and HIPAA compliant, independently verified by Oneleet.
SOC 2 Type 2 is an audit of how our controls actually operated over an extended period, not a point-in-time snapshot. Our security, privacy, and operational controls are continuously assessed against industry-standard frameworks, including HIPAA safeguards and the SOC 2 Trust Services Criteria.
Our compliance program covers data encryption at rest and in transit, access controls, audit logging, vendor risk management, and incident response procedures. You can review our current compliance status, policies, and third-party verification details in our Trust Center at trust.oneleet.com/eternal.
For firms that require one, we support Business Associate Agreements (BAAs) and provide the additional documentation most firms need to complete a vendor security questionnaire, on request.
View full details in our Trust Center.