Skip to main content
Wentzel Trust Center
Status: Aligned. Wentzel Investments LLC implements controls for SOC 2 Type 2 + ISO/IEC 27001:2022 but has not yet completed third-party audits. We use "Aligned" never "Compliant" or "Certified".

Information Security Policies

The 11 written policies below cover the Wentzel Investments LLC information security program. Canonical versions live in Confluence with formal review cadence, version history, and approval records. Customers under NDA can request a complete policy pack via the customer portal.

PolicyScopeSource
Information Security PolicyEveryone — root of the policy hierarchyConfluence COMP/Policies/information-security
Acceptable Use PolicyEveryone with access to Wentzel.ai systemsConfluence COMP/Policies/acceptable-use
Access Control PolicyIAM, application access, password and MFA rulesConfluence COMP/Policies/access-control
Change Management PolicyProduction changes, PR gates, deploymentConfluence COMP/Policies/change-management
Incident Response PolicySecurity and availability incidentsConfluence COMP/Policies/incident-response
Data Classification PolicyData categories, handling rules, retentionConfluence COMP/Policies/data-classification
Vendor Management PolicyOnboarding and reviewing third-party servicesConfluence COMP/Policies/vendor-management
Business Continuity PolicyOperating when normal operation is impairedConfluence COMP/Policies/business-continuity
Disaster Recovery PolicyRTO/RPO, backup, restoreConfluence COMP/Policies/disaster-recovery
Security Awareness Training PolicyTraining cadence and contentConfluence COMP/Policies/security-awareness-training
Privacy PolicyPersonal data handling, data subject rights, GDPR/CCPA postureConfluence COMP/Policies/privacy

Review cadence

Each policy is reviewed annually at minimum, plus after any material architecture change. Last-reviewed dates are tracked in the frontmatter of the canonical Confluence page. Material changes propagate to all in-scope repos via the WCB program.