How we protect your data.
Peach holds your customer records, your booking data, and a connection into your CRM. Here is exactly how that data is stored, who can see it, and how we keep it safe.
Compliance posture
Peach is operated under a SOC 2 Type II program (audit in progress, expected report Q3 2026) with controls modeled on AICPA Trust Services Criteria. Until the Type II report is issued, we operate under SOC 2 Type I-equivalent controls and our security policies are available for review under NDA.
Data in transit
All traffic between your browser, your CRM, and Peach is encrypted with TLS 1.2+ using strong cipher suites. We do not accept HTTP. Internal service-to-service traffic is encrypted with mTLS within an isolated VPC.
Data at rest
Customer data is encrypted at rest using AES-256. Database snapshots, object storage, and backups inherit the same encryption. Encryption keys are managed in a managed KMS with strict access logging.
Hosting & residency
Peach is hosted on tier-1 cloud infrastructure in US-East and US-West regions. Customer data does not leave the United States. We can provide region pinning on request for enterprise customers with specific residency requirements.
Authentication & access
Customer access to the Peach dashboard is protected with email + password and optional SSO (SAML / OAuth). Engineering access to production is restricted to a small named group, gated by hardware-key MFA, and logged. No engineer can access customer data without an audited break-glass workflow.
Sub-processors
We use a small set of vetted sub-processors (cloud hosting, database, telephony, email, analytics). The current list is available in our DPA and is updated when changes occur. We sign DPAs with each sub-processor and review their compliance posture annually.
Privacy & retention
We process personal data only as needed to operate the service. Customers can request export or deletion of their data at any time. Inactive customer data is purged on request or after termination per the DPA, whichever comes first.
Common questions.
Can we get a copy of your SOC 2 report?+
Yes. Type I documentation is available now under NDA. Type II is expected Q3 2026. Your account team will share it as soon as the report is issued.
Do you sign a Data Processing Agreement (DPA)?+
Yes. We sign a standard DPA for every paid customer. Custom redlines are reviewed for enterprise contracts.
Who at Peach can see our customer data?+
By default, no one. A small group of engineers has audited break-glass access for incident response only. Every access event is logged and reviewed.
What's your incident response process?+
We follow a documented IR runbook. Customers affected by a security incident are notified within 72 hours per our DPA. Post-incident reports are available on request.
Need our security packet?
Enterprise teams: our SOC 2 documentation, DPA, sub-processor list, and pen-test summary are available under NDA. Reach out and we'll send the bundle.