Import2 Trust Center
Import2 is committed to providing robust security
and privacy for our customers' data.
See resources
FAQs
What are the encryption standards leveraged for data in-transit
and data at-rest?
Import2 uses the strongest available encryption methods for your data during the
migration process.For data in-transit:
1. Our database uses SSL protocol
2. Browser data is encrypted using TLS/SSL protocols
3. The API connection to your connected apps depends on the vendor API
requirements, but are typically TLS/SSL protocols. If you wish to review the
specifics for your app, we recommend reviewing their developer API docs or getting
in touch with them directly.
Data at rest that is stored at Amazon S3 is encrypted utilizing AES-256 through SSES3.
Is HTTPS enabled for all webpages?
Yes, Import2 uses HTTPS for all webpages.
What Cloud Service Provider does Import2 use?
Import2 leverages several Cloud Service Providers. We utilize AWS for storage and our
cache uses Open Redis. Our app itself is hosted on Heroku.
Does Import2 perform security awareness training for all
employees annually?
Yes, Import2 is committed to ensuring all employees understand their role in combating
data security breaches, as well as a full understanding of the company’s protocols to
preserve the security of users’ data.
Do you perform backups on client data stored and processed in
the cloud environment?
As outlined in our data handling policy, Import2 does not store data on our servers. We
extract data, transform it in memory and load it into the destination app in real-time.
Moreover, we use temporary machines which means that as soon as your migration is
finished, the machine which was used for the migration gets deleted. Therefore, even
temporary log files are deleted.
Do contracts with all subcontractors include Non-
Disclosure/Confidentiality Agreements?
Yes, all contracts maintained by Import2 include Non-Disclosure Agreements.
Do you maintain commercial general liability insurance coverage?
Yes, Import2 maintains general liability coverage in the case of an incident.
Subprocessors

AWS
Cloud Hosting Services

Github
Developer Platform

Heroku
Cloud Platform as a Service

Intercom
Customer Service Platform

Stripe
Payment Processing Platform
Resources
Request a copy of our latest security and compliance resources and reports
SOC2 Type 2 Report
Period April 01, 2025 to June 30, 2025
Terms of Service
Privacy Policy
Data Processing Addendum
Compliance
Import2 is committed to providing robust security and privacy for our customers' data.

SOC 2 Type 2
Service Organization Controls (SOC 2) (Type II) trust services criteria for Security, Confidentiality and Privacy

GDPR
Protect the personal data and privacy of EU citizens for transactions that occur within EU member states

CCPA
California Consumer Privacy / Privacy Rights Act, is legislation designed to improve the data privacy of California residents