2001 Timberloch Pl, Ste. 500, The Woodlands, TX 77380-1375

Security

Compensation data is sensitive. We treat it that way.

Compensation data is among the most sensitive information your organization holds. Salary bands, performance ratings, equity grants, manager-employee relationships — all of it carries privacy, regulatory, and reputational weight.

CompAccelerator is built to keep compensation in HR’s hands. The same principle applies to security: a stack designed for it, audited against it, and committed to by us.

Certifications & Compliance

SOC 2 certified

Dartican maintains SOC 2 certification — independently audited controls covering security, availability, and confidentiality.

Built on Microsoft Azure US

CompAccelerator runs on Microsoft Azure’s US data centers. The platform has an extensive compliance portfolio including:

  • ISO 27001 / ISO 27018 / ISO 27701
  • SOC 1, SOC 2,
  • SOC 3
  • FedRAMP High
  • HITRUST CSF

Dartican inherits the operating environment’s audited security controls in addition to our own SOC 2 certification.

Privacy frameworks

Dartican monitors its security controls against the GDPR and CCPA frameworks through continuous compliance monitoring. Data Processing Agreements are available upon request.

Infrastructure & Hosting

CompAccelerator is hosted on Microsoft Azure US data centers, running on Azure SQL Database.

We use a defense-in-depth security architecture — layered controls spanning the physical data center, network, identity, and platform. Customer data access is denied by default and granted only on a just-in-time basis under audited policy.

Availability

CompAccelerator’s infrastructure provides a 99.99% uptime SLA at the database layer. Dartican’s customer agreements include availability commitments with service credits.

Data Ownership & Privacy

Your organization owns its compensation data at all times. Data is loaded, managed, and controlled entirely by your administrators — Dartican does not independently collect or process personal data beyond what you direct. You retain complete authority to add, update, or delete data at any point, without requiring action from Dartican. Employees with data subject rights requests contact your organization directly; you have the tools within the application to act on those requests immediately.

Data Protection

Encryption at rest

All customer data is encrypted with 256-bit AES (FIPS 140-2 compliant) using Azure SQL Database Transparent Data Encryption. Encryption is enabled by default at the database level; keys are managed by the Azure platform.

Encryption in transit

All connections to CompAccelerator use TLS 1.2 or higher.

Customer data isolation

Each customer’s compensation data is logically isolated within the Azure SQL Database environment.

Access Controls

Multi-factor authentication enforced

All Dartican administrative access to the Azure environment requires multi-factor authentication via Microsoft Authenticator. Phishing-resistant MFA is standard, not optional.

Microsoft Entra ID authentication

Identity is managed via Microsoft Entra ID (formerly Azure AD), providing centralized identity management, role-based access controls, and full audit trails on access decisions.

Least-privilege access

Dartican personnel access to customer environments is granted on a least-privilege basis, reviewed regularly as part of our SOC 2 controls.

Customer Controls & Product Security

Authentication & Single Sign-On

CompAccelerator supports Single Sign-On via SAML 2.0, enabling organizations to authenticate through their existing identity provider and enforce enterprise MFA and session policies at that layer. When an employee is removed from the central identity system, access to CompAccelerator is revoked automatically — no separate deprovisioning step required.

Cycle-level access management

Access within the application is governed at the compensation cycle level. HR administrators can load participant lists in bulk or configure access individually, giving HR teams direct control over who is included in each planning event without IT involvement. A user logging in sees only the cycles they have been explicitly granted access to. Role-based permissions and configurable dynamic roles allow access to be tailored to each organization’s structure.

IP access controls

Administrators can restrict application access by IP address using configurable allowlist and blocklist controls.

Audit visibility

Administrators have access to audit logs of login activity and administrative actions. Customer-accessible audit logs of compensation cycle activity give HR and comp teams a full record of who took what action during each planning cycle. Logs remain available for the lifetime of the cycle under your retention control.

Threat Detection & Monitoring

Advanced threat protection

Continuous monitoring watches for anomalous database activity, injection attempts, brute-force attacks, and suspicious access patterns, with immediate alerting on detected threats.

Vulnerability scanning

Built-in vulnerability assessment scanning runs against the database environment, surfacing misconfigurations and emerging risks for remediation.

External attack surface monitoring

Weekly automated vulnerability scanning covers Dartican’s external-facing infrastructure and the CompAccelerator application — testing against the OWASP Top 10 most critical web application vulnerabilities, with coverage continuously updated by a community of ethical security researchers to capture new vulnerabilities as they emerge.

Annual third-party penetration testing

Independent security firms test CompAccelerator and our infrastructure annually. Findings feed our remediation pipeline and our SOC 2 audit evidence.

Responsible disclosure

To report a potential security vulnerability, contact security@dartican.com. We acknowledge receipt within 3 business days and ask that you allow us reasonable time to investigate before public disclosure.

Backup & Recovery

Continuous backups via Azure SQL Database point-in-time restore

Transaction log backups are captured continuously, enabling restore to any point within the retention window.

Dartican maintains documented recovery objectives for both data loss and service restoration, tested through our annual disaster recovery program and documented as part of our SOC 2 controls.

Operational Practices

Personnel security

All Dartican personnel undergo background screening as a condition of employment. All employees and contractors complete annual security awareness training, and access to customer systems is revoked promptly upon separation through defined offboarding procedures. Training completion is a SOC 2-audited control.

Incident response

Dartican maintains a documented incident response plan covering detection, containment, eradication, recovery, and post-incident review. The plan is tested annually via tabletop exercise as part of our SOC 2 controls.

Continuous compliance monitoring

Dartican continuously monitors security controls, automates evidence collection, and maintains SOC 2 audit readiness year-round.

Cyber liability insurance

Dartican maintains cyber liability insurance coverage.

AI policy

Dartican maintains a formal AI policy governing the use of artificial intelligence within our products and operations. Customer data is never used to train AI models. A copy of our policy is available upon request.

Audit Logging

System and application logs capture security-relevant events and administrative actions across Dartican’s infrastructure, retained in accordance with SOC 2 requirements and available for incident investigation and audit evidence.

Customer Trust Commitments

What we commit to:

  • Your compensation data is yours. We do not sell, share, or monetize it.
  • We will notify you of any security incident affecting your data per our customer agreements.
  • Our SOC 2 reports and security documentation are available to customers on request, under standard NDA.

Security Questionnaire / Documentation Requests

Security teams evaluating CompAccelerator can request:

  • Current SOC 2 report
  • Security questionnaire responses (CAIQ, SIG, or your organization’s standard format)
  • Penetration test summary
  • Sub-processor list
  • Data Processing Agreement (DPA)
  • AI policy

See CompAccelerator in action

Security documentation request?

We respond to security questionnaires, SOC 2 report requests, and SIG/CAIQ formats.