How we protect customer data at First Touch. For security questionnaires, reports under NDA, or a copy of our Data Processing Addendum, email privacy@firsttouch.com.
First Touch maintains a SOC 2 Type II report covering the Security trust services criteria, available to customers and prospects under NDA. Our application has also been assessed against the OWASP Application Security Verification Standard through the App Defense Alliance CASA Tier 2 program (May 2026).
We commission an independent penetration test of the platform at least annually. Findings are triaged and remediated on defined timelines, and a summary of the most recent test is available under NDA.
The platform runs on Amazon Web Services in the United States. Production systems are protected by layered network controls and are logically isolated from corporate systems. Customer data is never stored on employee workstations or local servers.
Customer data is encrypted in transit using TLS and encrypted at rest across production databases, storage, and backups.
Access to production systems and customer data is limited by role and business need. Multi-factor authentication is enforced for privileged and production systems, access is reviewed periodically, and access is revoked promptly when personnel change roles or leave.
Production and non-production environments are segregated. Changes to production systems go through code review and testing before deployment, and emergency changes receive post-implementation review.
Security logs are generated and retained for production systems. Threat detection and vulnerability management processes identify material issues, and identified high-risk issues are tracked to remediation.
Backups are encrypted and protected by access controls. Disaster recovery and data restoration procedures are maintained and tested periodically.
Customers can delete their data or request deletion at any time. On termination, customer data is deleted from active systems within 30 days, with written certification of deletion available on request. Encrypted backups expire on a defined schedule with a maximum retention of six months.
A current list of the subprocessors that may process customer data is available at docs.firsttouch.com/approved-subprocessors. We provide notice of material changes as described in our Data Processing Addendum.
AI features are optional and can be disabled at the workspace level. Our Data Processing Addendum prohibits AI subprocessors from using customer data to train, fine-tune, or otherwise improve their models, and First Touch does not use customer data to train AI models.
Our Data Processing Addendum commits us to notifying affected customers of a personal data breach without undue delay, and in any event within 48 hours of becoming aware of it. Customers receive a named security contact and a direct escalation path.
Our standard DPA covers processor obligations, subprocessor management, international transfers under the EU Standard Contractual Clauses and the UK Addendum, and audit rights. Request a copy at privacy@firsttouch.com.
If you believe you have found a security vulnerability in a First Touch product, report it to privacy@firsttouch.com and we will investigate promptly.
Security questionnaires, reports under NDA, and privacy requests: privacy@firsttouch.com. Our Terms of Service and Privacy Policy are available on this site.