Welcome to the Ordergroove Trust Center. Ordergroove provides a Relationship Commerce Cloud, and this portal is designed to give you a clear understanding of our commitment to security and trust.
Here, you'll find comprehensive information about the security and privacy practices we have in place to protect our systems and your data. Our trust posture is built upon a foundation of rigorous controls and oversight. We regularly undergo independent examinations, such as the SOC 2® Report, which assesses our system's controls against the Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy. This report provides assurance that our service commitments and system requirements are met.
Ordergroove maintains a strong governance structure, with our Board of Directors demonstrating independence from management and actively overseeing the development and performance of internal controls, including security and privacy risks. We also emphasize integrity and ethical values, with clear policies, a code of conduct, and a disciplinary process for any violations.
Data protection is paramount. We have established a clear point of contact for privacy inquiries, allowing data subjects to submit requests or report incidents. Furthermore, we meticulously manage our relationships with third-party service providers and vendors, ensuring they meet our stringent requirements for preserving and protecting information through due diligence, risk assessments, and formal contracts that address security and privacy. While we utilize subservice organizations for cloud hosting, we ensure that complementary controls are in place to achieve our service commitments. To further mitigate risks, Ordergroove maintains cybersecurity insurance to address the financial impact of potential security incidents.
This Trust Center provides detailed evidence of these practices, offering transparency into how Ordergroove safeguards its systems and your information.
Risk Profile
We have secure, reliable hosting that customers can depend on. We are happy to provide details about our risk mitigation practices and recovery objectives upon request.
Reports
We may provide security-related reports upon request.
Self-Assessments
We are working on our security compliance. We can provide completed questionnaires upon request.
AI
We take the usage of AI seriously in our organization and work to ensure security and reliability of the AI.
ESG
We prioritize and take environmental, social, and governance (ESG) considerations seriously in our operations and decision-making processes.
Legal
We take legal matters seriously and we always engage our legal counsel to review all commercial activities. Please contact us if you have any questions.
Security Grades
We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.

