---
title: "Compliance & Trust | Phish Protection"
description: "Phish Protection is operated by DuoCircle LLC under our SOC 2 Type II program. Request the report, HECVAT, or our policy pack through the DuoCircle Trust Center."
image: "https://phishprotection.com/images/og-default.png"
canonical: "https://phishprotection.com/compliance/"
---

Compliance & Trust

#  Phish Protection runs on DuoCircle's compliance program.

 Phish Protection is built and operated by DuoCircle LLC. The Phish Protection service line is in scope for our SOC 2 Type II examination and has its own CSA STAR registry entry. All vendor-assessment documents are published in one place at the DuoCircle Trust Center.

### SOC 2 Type II

Annual examination since 2022 by Hancock Askew & Co, LLP. All four Trust Services Criteria: Security, Availability, Confidentiality, Processing Integrity. Report available under Bonterms Mutual NDA.

### CSA STAR Level 1

Phish Protection has its own entry in the Cloud Security Alliance public registry. CAIQ Lite, subset of CCM v4.1\. Renewed annually.

[View Phish Protection on CSA STAR →](https://cloudsecurityalliance.org/star/registry/duocircle/services/phishing-protection) 

### HECVAT Full

For colleges and universities, the Higher Education Community Vendor Assessment Toolkit, current version, available under NDA.

### Penetration testing

Annual third-party penetration test. Executive summary available under NDA.

## Need the SOC 2, HECVAT, or our policy pack?

Submit one request through the DuoCircle Trust Center. We use the standardized Bonterms Mutual NDA, published in advance so your legal team can review it before any conversation begins. We respond within one business day, and most often the same day.

[Request documents ](https://trust.duocircle.com/request/?source=phishprotection) [Browse Trust Center](https://trust.duocircle.com/) 

## Public, no NDA

- [CSA STAR registry entry for Phish Protection](https://cloudsecurityalliance.org/star/registry/duocircle/services/phishing-protection)
- [Security Overview](https://trust.duocircle.com/security/), plain-English version of our control set.
- [Policy catalog](https://trust.duocircle.com/policies/), the titles and review cadence of every policy in our information security program.
- [Subprocessor list](https://www.duocircle.com/legal/subprocessors/), every third-party vendor that processes personal data on our behalf.
- [Bonterms Mutual NDA](https://www.duocircle.com/legal/mutual-nda/), published in advance so you can read it before you ask.

 Phish Protection runs on the standardized [Bonterms Cloud Terms](https://www.duocircle.com/legal/cloud-terms/). Self-serve plans run on Bonterms Online Cloud Terms, accepted at sign-up. Enterprise plans run on a counter-signed Cover Page. Same balanced framework either way, no surprise additions.

Reviewed 2026-05-06.

See also: [Privacy Policy](https://www.duocircle.com/legal/privacy/) · [Cloud Terms](https://www.duocircle.com/legal/cloud-terms/) · [DPA](https://www.duocircle.com/legal/dpa/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"Phish Protection","url":"https://phishprotection.com","logo":{"@type":"ImageObject","url":"https://phishprotection.com/images/phishprotection-logo.png"},"description":"Advanced phishing protection and email security for businesses. Real-time threat defense, time-of-click protection, and seamless Office 365 integration.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"Phish Protection","url":"https://phishprotection.com","description":"Advanced phishing protection and email security for businesses. Real-time threat defense, time-of-click protection, and seamless Office 365 integration.","publisher":{"@type":"Organization","name":"Phish Protection","url":"https://phishprotection.com","logo":{"@type":"ImageObject","url":"https://phishprotection.com/images/phishprotection-logo.png"},"description":"Advanced phishing protection and email security for businesses. Real-time threat defense, time-of-click protection, and seamless Office 365 integration.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
{"@context":"https://schema.org","@type":"WebPage","name":"Compliance & Trust | Phish Protection","description":"Phish Protection is operated by DuoCircle LLC under our SOC 2 Type II program. Request the report, HECVAT, or our policy pack through the DuoCircle Trust Center.","url":"https://phishprotection.com/compliance/","isPartOf":{"@type":"WebSite","name":"Phish Protection","url":"https://phishprotection.com"},"about":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"mainEntity":{"@type":"ItemList","name":"Phish Protection compliance documents","itemListElement":[{"@type":"ListItem","position":1,"name":"SOC 2 Type II report (under NDA)"},{"@type":"ListItem","position":2,"name":"CSA STAR Level 1 (public)","url":"https://cloudsecurityalliance.org/star/registry/duocircle/services/phishing-protection"},{"@type":"ListItem","position":3,"name":"HECVAT Full (under NDA, higher education)"},{"@type":"ListItem","position":4,"name":"Information security policy pack (under NDA)"},{"@type":"ListItem","position":5,"name":"Penetration test executive summary (under NDA)"}]}}
```
