Compensation data is sensitive. We treat it that way.
Compensation data is among the most sensitive information your organization holds. Salary bands, performance ratings, equity grants, manager-employee relationships — all of it carries privacy, regulatory, and reputational weight.
CompAccelerator is built to keep compensation in HR’s hands. The same principle applies to security: a stack designed for it, audited against it, and committed to by us.
SOC 2 certified
Dartican maintains SOC 2 certification — independently audited controls covering security, availability, and confidentiality.
Built on Microsoft Azure US
CompAccelerator runs on Microsoft Azure’s US data centers. The platform has an extensive compliance portfolio including:
Dartican inherits the operating environment’s audited security controls in addition to our own SOC 2 certification.
Privacy frameworks
Dartican monitors its security controls against the GDPR and CCPA frameworks through continuous compliance monitoring. Data Processing Agreements are available upon request.
CompAccelerator is hosted on Microsoft Azure US data centers, running on Azure SQL Database.
We use a defense-in-depth security architecture — layered controls spanning the physical data center, network, identity, and platform. Customer data access is denied by default and granted only on a just-in-time basis under audited policy.
Availability
CompAccelerator’s infrastructure provides a 99.99% uptime SLA at the database layer. Dartican’s customer agreements include availability commitments with service credits.
Your organization owns its compensation data at all times. Data is loaded, managed, and controlled entirely by your administrators — Dartican does not independently collect or process personal data beyond what you direct. You retain complete authority to add, update, or delete data at any point, without requiring action from Dartican. Employees with data subject rights requests contact your organization directly; you have the tools within the application to act on those requests immediately.
Encryption at rest
All customer data is encrypted with 256-bit AES (FIPS 140-2 compliant) using Azure SQL Database Transparent Data Encryption. Encryption is enabled by default at the database level; keys are managed by the Azure platform.
Encryption in transit
All connections to CompAccelerator use TLS 1.2 or higher.
Customer data isolation
Each customer’s compensation data is logically isolated within the Azure SQL Database environment.
Multi-factor authentication enforced
All Dartican administrative access to the Azure environment requires multi-factor authentication via Microsoft Authenticator. Phishing-resistant MFA is standard, not optional.
Microsoft Entra ID authentication
Identity is managed via Microsoft Entra ID (formerly Azure AD), providing centralized identity management, role-based access controls, and full audit trails on access decisions.
Least-privilege access
Dartican personnel access to customer environments is granted on a least-privilege basis, reviewed regularly as part of our SOC 2 controls.
Authentication & Single Sign-On
CompAccelerator supports Single Sign-On via SAML 2.0, enabling organizations to authenticate through their existing identity provider and enforce enterprise MFA and session policies at that layer. When an employee is removed from the central identity system, access to CompAccelerator is revoked automatically — no separate deprovisioning step required.
Cycle-level access management
Access within the application is governed at the compensation cycle level. HR administrators can load participant lists in bulk or configure access individually, giving HR teams direct control over who is included in each planning event without IT involvement. A user logging in sees only the cycles they have been explicitly granted access to. Role-based permissions and configurable dynamic roles allow access to be tailored to each organization’s structure.
IP access controls
Administrators can restrict application access by IP address using configurable allowlist and blocklist controls.
Audit visibility
Administrators have access to audit logs of login activity and administrative actions. Customer-accessible audit logs of compensation cycle activity give HR and comp teams a full record of who took what action during each planning cycle. Logs remain available for the lifetime of the cycle under your retention control.
Advanced threat protection
Continuous monitoring watches for anomalous database activity, injection attempts, brute-force attacks, and suspicious access patterns, with immediate alerting on detected threats.
Vulnerability scanning
Built-in vulnerability assessment scanning runs against the database environment, surfacing misconfigurations and emerging risks for remediation.
External attack surface monitoring
Weekly automated vulnerability scanning covers Dartican’s external-facing infrastructure and the CompAccelerator application — testing against the OWASP Top 10 most critical web application vulnerabilities, with coverage continuously updated by a community of ethical security researchers to capture new vulnerabilities as they emerge.
Annual third-party penetration testing
Independent security firms test CompAccelerator and our infrastructure annually. Findings feed our remediation pipeline and our SOC 2 audit evidence.
Responsible disclosure
To report a potential security vulnerability, contact security@dartican.com. We acknowledge receipt within 3 business days and ask that you allow us reasonable time to investigate before public disclosure.
Continuous backups via Azure SQL Database point-in-time restore
Transaction log backups are captured continuously, enabling restore to any point within the retention window.
Dartican maintains documented recovery objectives for both data loss and service restoration, tested through our annual disaster recovery program and documented as part of our SOC 2 controls.
Personnel security
All Dartican personnel undergo background screening as a condition of employment. All employees and contractors complete annual security awareness training, and access to customer systems is revoked promptly upon separation through defined offboarding procedures. Training completion is a SOC 2-audited control.
Incident response
Dartican maintains a documented incident response plan covering detection, containment, eradication, recovery, and post-incident review. The plan is tested annually via tabletop exercise as part of our SOC 2 controls.
Continuous compliance monitoring
Dartican continuously monitors security controls, automates evidence collection, and maintains SOC 2 audit readiness year-round.
Cyber liability insurance
Dartican maintains cyber liability insurance coverage.
AI policy
Dartican maintains a formal AI policy governing the use of artificial intelligence within our products and operations. Customer data is never used to train AI models. A copy of our policy is available upon request.
System and application logs capture security-relevant events and administrative actions across Dartican’s infrastructure, retained in accordance with SOC 2 requirements and available for incident investigation and audit evidence.
What we commit to:
Security teams evaluating CompAccelerator can request:
Contact: security@dartican.com
We respond to security questionnaires, SOC 2 report requests, and SIG/CAIQ formats.