SOC 2 Service Information

Last Updated: April 26, 2022

Overview

Mperativ is the first strategic platform aligning marketing with sales, customer success, and finance on the cause and effect relationships between marketing activities and revenue outcomes. The SaaS platform centers key marketing metrics around revenue and connects marketing models to the rest of the business. Mperativ makes it possible to uncover data narratives across the entire customer journey, from initial engagement to close.

Mperativ is a Software-as-a-Service (SaaS) solution that removes the cost and complexity of building custom marketing analytics platforms. The Mperativ serverless data warehouse gets marketing out of the business of designing, managing, and building custom platforms. Users can achieve a 360° view of marketing, sales, finance, and customer success, all by using the data they already have. After just connecting a CRM instance, the platform can be up and running in a day.

All customer compute and data resources are isolated using Amazon cloud infrastructure. Each customer is provided a completely independent environment (i.e. -- no shared customer tenancy) to prevent any unauthorized access, whether accidental or malicious. Third-party auditors assess the security and compliance of Amazon's architecture as part of multiple AWS compliance programs. These include SOC, PCI, FedRAMP, HIPAA, and others.

Mperativ tenants are deployed in Silos (separate components, isolated subnets, etc.) promoting greater security, separation of concerns and flexibility for deployments. Silos are grouped in pods that also include shared services.


Mperativ uses security tools to scan our internal environment, system and services. We also engage professional security vendors to perform third-party penetration tests and audits of our environment on an annual basis, respectively, while internal system scans are performed quarterly. The Mperativ service is hosted in multiple data centers to provide redundancy. The data centers are geographically distributed and highly redundant in themselves.

Access to Customer Data

A subset of Mperativ personnel have access to customer data as necessary to support the platform and provide the service. Individual access is granted based on individual role and job responsibilities. Access to systems containing customer data is reviewed on a regular basis and monitored on an ongoing basis.

Secure Data Handling and Destruction

Our solution is hosted on one or more cloud-based Infrastructure-as-a-Service platforms. These cloud providers are responsible for the security of the underlying cloud infrastructure and Mperativ takes the responsibility of securing workloads we deploy inside the cloud infrastructure. Cloud providers monitor and audit computing environments continuously, with certifications from accreditation bodies across geographies and verticals, including ISO 27001, FedRAMP, DoD CSM, and PCI DSS. Any device storing any data is subjected to data-at-rest encryption. The service makes use of code-level logic and permissions to segregate customer data.

Customer Responsibilities

As a user of Mperativ, customers should be proactive in recognizing the value and sensitivity of the information provided by the service and the need to safeguard such data appropriately. This document details the Mperativ customer responsibilities as they relate to use of the Mperativ Revenue Marketing Platform. It is the responsibility of Mperativ customers to familiarize themselves with the information and procedures set forth below and comply with them.

Safeguarding of Assets and Information

To safeguard information assets and policy enforcement capabilities available in Mperativ, the customers’ IT governance processes should include end-user training regarding appropriate use and awareness of the need for securing access to their Mperativ account credentials. As with most cloud services, access to Mperativ requires a login ID and password or integration with a Single-Sign-On (SSO) provider. When an organization subscribes to Mperativ, it is the customer’s responsibility to manage which users should be given access to the service. Customers should also define when access should be removed. For example, removing access upon termination of employment or as part of departmental changes that result in change of duties or responsibilities. Only valid account credentials should be used by authorized users to access  Mperativ; users should not share authentication credentials.

Mperativ should be considered sensitive and confidential by users of the service. Users should follow information security best practices to ensure that access to their account credentials is appropriately limited, and the information and functionality provided by Mperativ is protected from unauthorized use. Mperativ users are responsible for maintaining the security and confidentiality of their user credentials (e.g., Login ID and Password), and are responsible for all activities and uses performed under their account credentials whether authorized by them or not. By establishing user credentials and accessing the platform, users of Mperativ agree to comply with these requirements to safeguard assets and account information.

Service Termination

Mperativ subscriptions can be terminated by contacting support@mperativ.io.

Password Management

Mperativ is accessible via the Internet. As a result, great care must be exercised by Mperativ users in protecting their subscription against unauthorized access and use of their credentials. By establishing user credentials and accessing the service, users agree to proactively protect the security and confidentiality of their user credentials and never share service account credentials, disclose any passwords or user identifications to any unauthorized persons, or permit any unauthorized person to use or access their Mperativ accounts. Any loss of control of passwords or user identifications could result in the loss or disclosure of confidential information and the responsible account owner(s) may be liable for the actions taken under their service account credentials whether they authorized the activity or not. Additionally, when establishing Mperativ account credentials, end users are required to establish strong passwords following password strength and complexity best practices; passwords should not be easily guessable.

Reporting Operational Issues

All Mperativ services are monitored 24×7 to meet our service commitments. All planned maintenance will be performed in accordance with the Mperativ maintenance plan, which is communicated to customers when they sign up for the service. If there is a need to perform emergency maintenance for a vulnerability or bug fix, we will notify customers prior to the work being performed. To get updates in real-time, customers can subscribe to email notifications. On the occasion that Mperativ customers observe performance issues, problems or service outages, they can contact support@mperativ.io or open a support ticket to report such issues.

Incidents and Breaches

By establishing Mperativ account credentials or accessing its service, customers agree to notify Mperativ immediately of any security incident, including any suspected or confirmed breach of security. Also, users of the service agree to log out or exit the service immediately at the end of each session to provide further protection against unauthorized use and intrusion. Mperativ customers should also notify Mperativ immediately if they observe any activity or communications in other forums that may indicate that other Mperativ customers have had their accounts compromised. Lastly, Mperativ encourages users to practice responsible disclosure by notifying Mperativ of any potential or confirmed security vulnerabilities. Mperativ is dedicated to providing secure services to clients, and will triage all security vulnerabilities that are reported. Furthermore, Mperativ will prioritize and fix security vulnerabilities in accordance with the risk that they pose.

Compliance Issues

Regulatory requirements and industry mandates are continuously increasing in scope & depth and can vary from industry to industry. Mperativ users agree to abide by the regulatory requirements, industry mandates, and other compliance requirements imposed on their organizations and understand that use of cloud-based services does not exclude the organizations from responsibilities for restricting access to application information and functionality.

Responsible Disclosure Policy

Mperativ is dedicated to keeping its cloud platform safe from all types of security issues thereby providing a safe and secure environment to our customers. Data security is a matter of utmost importance and a top priority for us. If you believe you have discovered a security flaw in the Mperativ or the underlying infrastructure, we appreciate your support in disclosing the issue to us in a responsible manner. Our responsible disclosure process is managed by the security team at Mperativ. We are always ready to recognize the efforts of security researchers by rewarding them with a token of appreciation, provided the reported security issue is of high severity and not already known to us. When reporting the security vulnerability to our Security team, please refrain from disclosing the vulnerability details to the public outside of this process without explicit permission. Please provide the complete details necessary for reproducing the issue. We determine the risk of each vulnerability by assessing the ease of exploitation and business impact associated with the vulnerability.

Response

As a security researcher, if you identify or discover a security vulnerability in compliance with the responsible disclosure guidelines, Mperativ commits to:

  • acknowledge the receipt of the reported security vulnerability in a timely fashion
  • acknowledge the receipt of the reported security vulnerability in a timely fashion
    notify you when the vulnerability is remediated
  • extend our gratitude by providing a token of appreciation in supporting us to make our customers safer and more secure

Please report security issues to: security@mperativ.io

Privacy Policy

You can view our Privacy Policy at https://www.mperativ.io/legal/privacy-policy. The Policy in effect at the time you use our website affects how we may use your information. Our business

Whistleblower Policy

When team members notify a supervisor, manager, or an appropriate government or law enforcement agency that they have reason to believe their employer is violating a state or federal statute, or violating or not complying with a state or federal rule or regulation, those team members are protected from retaliation. As such, Mperativ, Inc. has a strict policy that prohibits retaliation against team members who make such reports while employed in any form of employment. The Corporation also does not permit retaliation against team members who refuse to participate in an activity that would result in a violation of a state or federal statute, or a violation or noncompliance with a state or federal rule or regulation.
If you have information regarding possible violations of state or federal statutes, rules, or regulations, or violations of fiduciary responsibility by the Corporation, we encourage you to report it immediately to your Managers or to the CEO. Alternatively, you may contact the California State Attorney General's Whistleblower Hotline at (800) 952-5225. The Attorney General will refer your call to the appropriate government authority for review and possible investigation.

Whistleblower ssues can be reported via the Mperativ Code Of Conduct Violations Form, hr@mperativ.io or +1 (415) 874-0512.

Data Retention

By default, we will retain your data indefinitely. You can ask to close your account by contacting us at support@mperativ.io and we will delete your information upon request. We may, however, retain information, including personal information to the extent applicable, for an additional period as is required under applicable laws, for legal, tax, or regulatory reasons, or for legitimate and lawful business purposes.

Changes to our Privacy Policy

The Privacy Policy in effect at the time you use the Mperativ service governs how we may use your information. Our business may change from time-to-time. As a result, at times it may be necessary for Mperativ to make changes to the Privacy Policy. Mperativ reserves the right to update or modify the Privacy Policy at any time. If we make material changes we will post the updated policy on this page with an updated Effective Date. Please review our Privacy Policy periodically, and especially before providing your data to Mperaiv through our website or by registering for the Mperativ service. Your continued use or access to the Mperativ corporate website or the Mperativ service after any changes or revisions to the Privacy Policy shall indicate your agreement with the terms of the revised Privacy Policy.

Changes to our Service Commitments

While rare, we may occasionally change our service terms. This includes, but is not limited to, our commitments regarding security, confidentiality, performance or availability. In the event that we intend to make such changes, we will notify the business contact for the organization at the email address we have within our customer database at least thirty (30) days prior to such changes taking effect.

Contacting Mperativ

For general inquiries, please contact us at info@mperativ.io.

Animated Mperativ M Icon