Where we stand today
SOC 2 Type II alignment
We operate against SOC 2 Type II controls across security, availability, and confidentiality trust criteria. Our formal Type II audit is in progress with completion targeted for Q4 2026; the underlying control set, evidence collection, and continuous monitoring are already in production via Vanta.
GDPR & CCPA
Our standard Data Processing Addendum (DPA) covers GDPR Article 28 processor obligations and CCPA service-provider requirements. EU standard contractual clauses (SCCs) are available on request for cross-border transfers.
HIPAA
For healthcare engagements, we sign a Business Associate Agreement (BAA) and operate against HIPAA Security Rule administrative, physical, and technical safeguards. We do not process PHI outside client-approved cloud environments (typically AWS or Azure BAAs).
PCI DSS
We do not directly handle cardholder data. For engagements touching payment flows, we architect to keep PANs out of scope (tokenization via Stripe, Adyen, Braintree, or PCI-compliant gateways) and support SAQ-A / SAQ-A-EP scoping.
Security controls
SSO (Okta / Google Workspace / Microsoft Entra), MFA required for all engineers, hardware keys for admin roles.
Managed devices with disk encryption, EDR (SentinelOne / CrowdStrike), automated patching, and remote wipe.
Least-privilege via role-based access control. Client production access is time-bound, logged, and requires explicit ticket-linked justification.
No plaintext secrets in code or chat. Vault or cloud-native secret managers (AWS Secrets Manager, Azure Key Vault, GCP Secret Manager) with rotation policies.
Two-person review required for merge to protected branches. Automated SAST (CodeQL / Semgrep) and dependency scanning (Snyk / Dependabot) on every PR.
AES-256 at rest via managed cloud KMS. Client data isolated per engagement — no shared multi-tenant storage.
TLS 1.2+ enforced for all client-facing and internal service-to-service traffic. mTLS for service meshes where architecturally appropriate.
Centralized log aggregation with 90-day hot retention and 1-year cold retention. Immutable audit trail for privileged access events.
Automated daily backups with point-in-time recovery. Quarterly restore drills against a canary dataset — documented, dated, and reviewable.
Continuous dependency scanning, weekly automated pen-scan (Detectify / Intruder), annual third-party penetration test.
How we handle security incidents
- 01 · Detect
Automated alerting via Datadog + Sentry, plus 24/7 on-call rotation for managed systems.
- 02 · Triage
Incident commander assigned within 15 minutes for Sev-1, 1 hour for Sev-2.
- 03 · Contain
Isolate affected systems, rotate credentials, and preserve forensic evidence.
- 04 · Notify
Client notification within 24 hours for any confirmed security event affecting their data, per DPA terms.
- 05 · Remediate
Root-cause analysis published within 5 business days; corrective action tracked to closure.
- 06 · Learn
Post-incident review with the client, blameless internal review, and control updates.
Our subprocessors
The third-party services NextGen uses to operate. Client-specific subprocessors (analytics, error monitoring, email) are provisioned inside the client's own accounts and are not listed here. We notify clients 30 days in advance of any material subprocessor change.
| Subprocessor | Purpose |
|---|---|
| Amazon Web Services | Cloud infrastructure (client-directed regions) |
| Microsoft Azure | Cloud infrastructure (client-directed regions) |
| Google Cloud Platform | Cloud infrastructure (client-directed regions) |
| GitHub | Source control, CI/CD, code review |
| Vanta | Continuous compliance monitoring |
| 1Password | Secrets and credential vaulting |
| Google Workspace | Email, docs, calendar |
| Slack | Internal and client communications (no PHI/PII) |
| Sentry | Error monitoring and alerting |
| Datadog | Observability and logging |
Where your data lives
Client-owned infrastructure
Production data — customer records, PHI, PII, PCI-adjacent flows — lives exclusively in infrastructure owned and controlled by the client (their AWS, Azure, or GCP account). NextGen engineers access these systems via time-bound, logged, least-privilege credentials issued by the client's IAM.
NextGen-side data
The only client data resident inside NextGen systems is what's necessary to run the engagement: contact information, contracts, source code (via GitHub), and business-level documentation. No production customer data is ever copied to NextGen systems, laptops, or personal accounts.
Frequently asked questions
- Do you sign our vendor security questionnaire?
- Yes. Send it to security@nextgencodingcompany.com and we'll return a signed response within 3 business days for standard questionnaires (SIG Lite, CAIQ, custom). More complex enterprise-vendor questionnaires may take 5-7 business days.
- Do you sign a Data Processing Addendum (DPA)?
- Yes — our standard DPA covers GDPR Article 28, CCPA service-provider terms, and standard confidentiality obligations. We're happy to sign the client's DPA instead if the terms are reasonable.
- Do you have cyber liability insurance?
- Yes. Certificate of insurance available on request — $5M cyber liability, $5M errors & omissions, $2M general liability.
- Where are your engineers located?
- By default, all engineers on U.S. client engagements are located in the United States. Nearshore (LATAM) engineers are available on request with client approval and updated DPA scoping.
- How do you handle offboarding at engagement end?
- Within 5 business days of engagement close: revoke all client-issued credentials, delete NextGen-side working copies of source and documentation older than retention policy, and provide a written offboarding attestation.
Need the signed vendor packet?
Contact us with your vendor security questionnaire, DPA, or MSA and we'll return a signed response within 3 business days. For time-sensitive procurement, mention it in the request and we'll prioritize.

