

Our Security Program
At Paminga, the security of our customers' data is treated as a core responsibility, not an afterthought. Security practices are built into how we operate, not bolted on.
Paminga maintains a SOC 2 Type II report and ISO 27001 certification covering our information security program. Full reports and certificates are available upon request, subject to a mutual NDA.
All customer communications are encrypted in transit. Backups are encrypted with high-grade encryption and tested quarterly by restoring a complete database to validate data integrity. Backup data is not transferred across international borders.
Access to customer data is restricted to authorized personnel and is removed immediately upon termination or role change. Authentication is protected by multi-factor authentication, and system passwords follow NIST SP 800-53 standards for length, complexity, and expiration, with account lockout after repeated failed attempts.
Paminga's network and production systems are continuously monitored, with intrusion detection in place to identify and block suspicious traffic. We perform regular network vulnerability assessments using industry-standard scanning tools and maintain an active vulnerability remediation program. Independent third parties conduct network penetration testing at least annually. Critical, exploitable vulnerabilities are patched on a timely basis, and all endpoints run antivirus protection with current signature updates.
Customer data is hosted with data center providers that are ISO 27001:2022 certified, with redundant power (UPS and backup generation), advanced fire suppression, and redundant climate control systems designed to maintain consistent operating conditions.
Paminga maintains documented policies for responding to events that could affect the availability, integrity, or confidentiality of customer data, including system failure or natural disaster.
Each hosting environment runs within a single AWS region, and infrastructure is built with redundant network and storage paths. Recovery is built on encrypted, in-region snapshots and validated restores rather than cross-region failover — a deliberate choice. The complexity of cross-region failover is permanent, and for the failure modes we actually plan for, a tested restore is the more dependable answer.
All access to production systems is logged, and network security logs are retained for 180 days. In the event of a security breach, Paminga notifies affected customers within 72 hours of becoming aware of the incident, along with a written description of the breach and the steps taken to address it.
All Paminga personnel and contractors undergo background checks, including criminal, employment, and reference verification. Security and privacy training is required annually for all personnel. Third parties are never given access to Paminga's development or production servers.
Data Residency // US or EU
Paminga can host your account entirely in AWS Frankfurt, Germany (eu-central-1). Your contacts, activity history, digital assets, and the application that processes them all live in the EU, and email is sent through EU sending infrastructure.
The EU stack is a separate AWS account with its own network, databases, object storage, and credentials — there is no replication to and no network path from our US environment. EU application logs stay in region, with capped retention. Your CRM and ad-platform integrations authorize and sync through EU hosts rather than detouring through the US. Hosting region is set when we provision your account.
One exception is worth stating plainly. Paminga's AI features run on Anthropic's Claude models, and Anthropic publishes no EU endpoint — so when an AI feature runs, the material it works from is processed outside the EU on either hosting region. Anthropic is named on our sub-processor list, and under its commercial terms your content is not used to train its models. The EU hosting details below cover what that means in practice.
Read the EU Hosting DetailsLegal
Our Data Processing Addendum sets out how Paminga processes personal data on your behalf, including the terms that apply when you object to a sub-processor.
Our sub-processor list names every third party authorized to process personal data for Paminga's services. You can subscribe to be notified whenever it changes.
Built with pride in Denver, Colorado, USA
Copyright © Paminga, Inc. 2026