Last updated August 2026
Security & Trust
An honest description of how we operate -- not a list of certifications we haven't earned yet.
Access control
Access to client information and systems is limited to the team members who need it for their role, and every team member signs a confidentiality agreement before working on client-facing programs.
Data handling
Client and customer data is handled with GDPR principles as our baseline, regardless of where a client is based: data minimization, purpose limitation, and clear retention practices for every program we run.
Quality and reporting discipline
Every operating program is built around structured QA review and transparent performance reporting back to the client -- visibility into how a program is actually running, not just a monthly summary.
Systems architecture
Our internal systems are designed with security as a starting requirement, not an afterthought: role-based access, isolated environments between clients, and no unnecessary exposure of internal tools to the public internet.
Where we are today
ER CONNEXT is a growing operation. We have not yet completed a third-party security certification audit (such as ISO 27001 or SOC 2), and we won't claim one until it's genuinely earned. What's above reflects how we actually build and run our operations today. If a formal certification is a requirement for your program, tell us -- we're glad to discuss a path to it as part of a partnership.
Contact
Security or compliance questions can be sent to sales@erconnext.com.