Skip to main content
Wentzel Trust Center
Status: Aligned. Wentzel Investments LLC implements controls for SOC 2 Type 2 + ISO/IEC 27001:2022 but has not yet completed third-party audits. We use "Aligned" never "Compliant" or "Certified".

Confidentiality

Confidentiality covers identification of confidential data, protection during processing, and disposal. We handle customer integration credentials, source code (CARL Scanner ephemeral), and product PII.

Data classification

ClassExamplesStorage
@publicMarketing, OSS code, this trust centerStatic / CDN
@internalSystem identifiers, internal configsCloudWatch / Postgres (KMS)
@piiCustomer email, name, IPPostgres column-level KMS
@phiHIPAA-covered (Humanome only — separate scope)Bedrock-routed paths only
@financialStripe customer/subscription IDs (PAN never on our origin)Stripe + LLC merchant accounts
@secretCredentials, API keys, KMS materialAWS Secrets Manager only

Controls

ControlAreaStatusEvidence
WCB-CC-12TLS 1.3 in transitAlignedCloudflare + ALB enforced
WCB-CC-13KMS at rest — customer-managed CMKsAlignedPer-data-class key separation
WCB-CC-14Secrets management — AWS Secrets ManagerAlignedNever in source; rotation per docs/secrets/rotation-plan.md
WCB-CC-24Data classification labelsAligned@public/@internal/@pii/@phi/@financial/@secret
WCB-CC-25Data retention & disposalAlignedCascading delete via packages/data-export
WCB-CC-36NDA agreements with contractorsAlignedPer-contractor + Trustee Agreement (Glenda Nicole Ramsey)