Security & compliance
Security Your IT Team Can Trust
Recognize is ISO 27001:2022 certified and GDPR compliant, with single sign-on, encryption, and a live trust center, so rolling out recognition never means adding risk.
Visit our trust centerBuilt-in protection
Security at every layer
ISO 27001:2022 certified
Our information security management system is independently audited to the ISO 27001:2022 standard. The certificate is available on request.
GDPR compliant
Recognize is built to meet GDPR obligations for handling employee data, with data subject request processes in place.
Live trust center
Our Vanta-powered trust center documents our security controls, policies, and subprocessors in real time.
Single sign-on
SAML and OAuth single sign-on let employees use existing credentials, with automated user provisioning.
How we protect your data
Encryption everywhere
Data is encrypted in transit and at rest across the platform.
Least data by design
Recognize is designed to process only the employee information needed to run recognition, not customer PII, payment data, or health records.
Trusted subprocessors
We rely on a small set of U.S.-based subprocessors, including AWS, Twilio, Mailchimp, and Zendesk, all documented in our trust center.
Independent testing
We maintain penetration testing, with an attestation available on request.
Documentation for your review
Our trust center provides self-serve access to our security posture. We can also share our ISO 27001 certificate and penetration test attestation on request. For security questions, email security@recognizeapp.com.
Visit the trust center Book a security review