Germinate Logo

Trust Center

Start your security review
View & download sensitive information
Ask for information
ControlK

Welcome to Germinate's Trust Center. Germinate is a custom software development agency established in 2008, serving various clients and industries. This Trust Center is designed to provide a clear and accessible overview of our security and trust practices, demonstrating our commitment to protecting your information.

At Germinate, we prioritize the security and privacy of the data we handle. Our comprehensive approach to trust is built upon robust policies and operational practices. We have defined policies for managing changes across the organization to minimize disruptions and a structured software development life cycle that includes tracking, testing, approving, and validating changes. Our applications are developed following secure coding guidelines.

Data protection is a cornerstone of our operations. We have a strong focus on access control, requiring annual reviews and specific forms for new hires and transfers. To safeguard sensitive systems and applications, we mandate multi-factor authentication, utilizing user IDs, passwords, one-time passwords, and/or certificates. We also have a key management process in place to support our use of cryptographic techniques. Our authentication policies guide users on selecting strong credentials, protecting them, and avoiding reuse.

For our workforce, we maintain an Acceptable Use Policy that all employees must acknowledge upon hire. Contractors are also required to read and acknowledge our Code of Conduct and Acceptable Use Policy, and they must pass a background check. We also carefully manage our vendor relationships, maintaining a directory of key vendors and reviewing critical vendor compliance reports annually.

Furthermore, Germinate operates as a Business Associate under HIPAA, meaning we have specific policies and procedures in place to handle Protected Health Information (PHI). We ensure that written agreements are in place with any third parties who create, receive, maintain, or transmit PHI on our behalf, clearly defining their responsibilities and mandating security controls and data protection policies. Our CTO and CEO are responsible for ensuring these commitments are met.

This Trust Center provides detailed information on these and other practices, offering transparency into how Germinate maintains a secure and trustworthy environment.

Risk Profile

We have secure, reliable hosting that customers can depend on. We are happy to provide details about our risk mitigation practices and recovery objectives upon request.

Reports

We may provide security-related reports upon request.

Self-Assessments

We are working on our security compliance. We can provide completed questionnaires upon request.

AI

We take the usage of AI seriously in our organization and work to ensure security and reliability of the AI.

ESG

We prioritize and take environmental, social, and governance (ESG) considerations seriously in our operations and decision-making processes.

Legal

We take legal matters seriously and we always engage our legal counsel to review all commercial activities. Please contact us if you have any questions.

Security Grades

We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.

Built onSafeBase by Drata Logo