Datafold Security Addendum
| Effective | Status |
|---|---|
| October 2, 2026 | Current version |
This Security Addendum (the "Addendum") is incorporated by reference into the agreement under which Datafold, Inc. ("Datafold") provides the Services to Customer, being the Datafold Master Subscription Agreement as amended for Professional Services or another agreement that incorporates this Addendum (the "Agreement"), and into the Datafold Data Processing Addendum (the "DPA"), of which it forms Annex II.
1. Purpose, scope and updates
1.1 This Addendum describes the security program, attestations and technical and organizational measures (the "Security Measures") Datafold maintains to protect Customer Data and the Services, as of its version date. It is a description, not a warranty: the warranties, the covenant to maintain the program and the limits of liability are in the Agreement. It covers what Datafold operates under the elected Deployment Model (Section 4) and Datafold Personnel wherever they work; as the Agreement provides, Datafold is not responsible for Customer Data in Customer's environment or a Customer-Provided Model Endpoint except to the extent a Security Incident arises from Platform components Datafold operates or from Datafold Personnel, devices or credentials. Free trials of the Service are excluded; Services under a Statement of Work, including a proof of concept, are included.
1.2 Updates. Datafold may update this Addendum by posting the new version, with its version history, at the URL above, provided no update materially diminishes the overall protection of Customer Data during the term; the version in effect on the date an agreement incorporates this Addendum governs until so updated.
1.3 Customer-specific requirements recorded in an Order Form, Statement of Work or partner agreement prevail over this Addendum to the extent stated.
1.4 Application. This Addendum is published for reference. It binds Datafold only under an Agreement or DPA that incorporates it, and it creates no rights for anyone else.
2. Definitions
2.1 Capitalized terms not defined in this Addendum have the meanings given in the Agreement or, for terms the Agreement does not define (Services, Platform, Documentation, Inputs, Outputs, Security Incident, Confirmation, Confirmed Incident, Sensitive Data, Usage Data, Account Data and Trust Portal), in the DPA. Deployment Model and Partner-Access have the meanings given in Section 4.
3. Security program and governance
3.1 Datafold maintains a written, risk-based information security program of administrative, technical and physical safeguards for the confidentiality, integrity and availability of Customer Data and the Services, aligned to the AICPA Trust Services Criteria for Security, Availability and Confidentiality and documented in an Information Security Policy and supporting policies.
3.2 Policies are approved by management at least annually, available to all Datafold Personnel and backed by a disciplinary process; a designated security lead reports to executive management, a security council reviews access exceptions and risk decisions, and an enterprise risk assessment is performed at least annually.
4. Deployment Models and shared responsibility
4.1 Deployment Models. Each Order Form and Statement of Work elects one Deployment Model by the label below, the version of this Addendum in effect and whether Partner-Access applies. In every Deployment Model Datafold operates the Platform; in Single Tenant Customer-hosted, Customer provides and operates the infrastructure it runs on and grants Datafold the access the Order Form or Statement of Work states. A former or descriptive name is read as the label shown.
| Deployment Model | What it is | Former names |
|---|---|---|
| SaaS | Datafold hosts and operates the Platform on shared, multi-tenant infrastructure in Datafold's cloud account | "Datafold Cloud", "multi-tenant SaaS", "SaaS deployment", "Datafold-Hosted Multi-Tenant", "DM-1" |
| Single Tenant Datafold-hosted | Datafold hosts and operates a dedicated instance of the Platform for Customer in Datafold's cloud account | "Dedicated Cloud", "Datafold-Hosted Single-Tenant", "Single-Tenant" in Datafold's account, "DM-2" |
| Single Tenant Customer-hosted | The Platform runs in Customer's cloud account or environment, on infrastructure Customer provides, and Datafold operates it through the access Customer grants | "Customer-Managed", "Customer VPC", "self-hosted", "on-premise", "single-tenant VPC", "Single-Tenant" in Customer's account, "DM-3", "DM-3a", "DM-3b" |
4.2 Partner-Access overlay. "Partner-Access" (formerly the "partner-access model" or "arrangement") is not a Deployment Model but an overlay on any Deployment Model under which Datafold Personnel work through accounts, devices or tooling issued by Customer, its Affiliate, a customer of Customer or a partner. The Section 4.4 allocation then applies, except that (a) Customer is responsible for the security of what it or the partner issues and for the acceptable-use, export-control and endpoint policies governing it, with which Datafold Personnel comply, using it only as issued and only for the Services, while Datafold-managed devices and Datafold-issued credentials remain Datafold's, and Datafold notifies Customer when an individual no longer needs access; (b) where Customer or the partner so requires, Datafold Personnel use only the AI tooling it authorizes (Section 16.4); and (c) Datafold remains responsible for the conduct of Datafold Personnel.
4.3 Attributes referenced by the Agreement. Where a clause applies to a Deployment Model "that the Security Addendum identifies as" having an attribute, this table decides.
| Attribute (referencing clause) | SaaS | Single Tenant Datafold-hosted | Single Tenant Customer-hosted |
|---|---|---|---|
| Hosted in Customer's environment | No | No | Yes |
| Multi-tenant, shared infrastructure (Section 8.2; BAA Section 1) | Yes | No | No |
| Dedicated infrastructure in Datafold's account (BAA Section 1) | No | Yes | No |
| Within Datafold's SOC 2 attestation (Section 19) | Yes: its production environment | Not separately described in the current report; the Trust Portal states what each report covers | No |
| Available for free trials | Yes | No | No |
| Region set by (Order Form or SOW, as the DPA provides) | The regions the Subprocessors document, or the Order Form | Order Form or SOW | Customer |
| Deletes the deployment infrastructure at the end of the Services (as the Agreement and the DPA provide) | Datafold | Datafold | Customer, unless the SOW provides otherwise |
4.4 Shared-responsibility matrix. Where this Addendum states a control whose performance varies by Deployment Model, this matrix determines who performs it; what this Section 4 "allocates" to a party means this allocation, and Section 4.2 modifies it under Partner-Access. Controls not listed are Datafold's for the Platform and Customer's for its own environment and users (Section 20). D = Datafold performs and is responsible; C = Customer; D+C = per the numbered note.
| Control area | SaaS | Single Tenant Datafold-hosted | Single Tenant Customer-hosted |
|---|---|---|---|
| 1. Infrastructure: data-center physical security (the cloud provider's, whose attestations the responsible party reviews); cloud account, IAM, network and VPC; cluster, compute and storage; node, OS and cloud-configuration patching and scanning; infrastructure logs and monitoring; ingress TLS and DNS; edge protection; Model Provider egress controls; Datafold's remote-access path; infrastructure disaster recovery and testing | D | D | C |
| 2. Platform deployment: deployment configuration per the deployment guide; applying Platform releases; encryption at rest on Platform data stores; Platform application logs and monitoring | D | D | D |
| 3. Cloud KMS keys for Platform data stores, disks and backups | D | D+C (1) | C |
| 4. Storage and use of Customer's source and target credentials in the Platform | D | D | D+C (2) |
| 5. Platform log retention period | D | D | D+C (3) |
| 6. Backups of Platform data stores (Sections 4.5(b) and 14) | D | D | D+C (4) |
| 7. Release pipeline and deployment automation | D | D | D+C (5) |
Notes: (1) Datafold holds and rotates the keys unless the Order Form provides for customer-managed keys, which Customer holds and rotates and Datafold configures the Platform to use. (2) Customer provides the secrets store; Datafold configures the Platform to use it, generates the application-layer key that encrypts the credentials (Section 6.3), places it in that store and keeps it nowhere else. (3) Datafold configures the period the Order Form or SOW states; logs in Customer's account follow Customer's configuration. (4) Customer provides the backup storage; where backups are encrypted with keys Datafold holds (Section 4.5(b)), Datafold protects the keys and Customer holds the backups. (5) Datafold runs the automation; Customer approves and provides the network path and access into its account.
4.5 Model-specific operational rules. (a) Telemetry and logs. In SaaS and Single Tenant Datafold-hosted, operational telemetry and logs are processed in Datafold's environment and by the operations Subprocessors on the Subprocessor List. In Single Tenant Customer-hosted, Customer Data remains within Customer's environment except (i) telemetry and logs sent to those Subprocessors, designed not to contain Customer Data values but possibly including identifiers and, on error, query-text fragments, which Datafold treats as Customer Data (Section 9) and which Customer may require to be retained within its environment by so specifying in the Order Form or SOW; (ii) requests to the Customer-Provided Model Endpoint, where elected, or otherwise to the Datafold-Managed Model Provider or Providers Datafold selects under the Agreement; and (iii) the backup flow in (b), where so configured. (b) Backups. Section 14 governs; Single Tenant Datafold-hosted backups are as the Order Form provides; Single Tenant Customer-hosted backups stay in Customer's account and, where so configured, are encrypted with keys Datafold holds in the Subprocessor identified for that purpose on the Subprocessor List. (c) Connectivity. Connectivity to Customer's source and target systems uses the encrypted method Customer selects per the Documentation (IP allow-listing, the cloud provider's private connectivity, SSH tunnel or VPN); Datafold uses least-privilege, dedicated credentials, revocable by Customer on notice subject to the SOW.
5. Personnel security
5.1 Screening. Datafold requests a background check for each employee before, or within thirty (30) days after, the employee's start date, including a criminal-record check and reference checks to the extent lawful in the individual's jurisdiction, and any adverse or incomplete result is evaluated and decided by Datafold's executive management; an individual contractor with privileged or administrative access to production systems or to Customer Data is subject to a background check, or provides evidence of an acceptable background, proportionate to that access. Datafold completes checks an Order Form or Statement of Work additionally requires before access, and keeps screening records three (3) years after access ends.
5.2 Confidentiality and training. Datafold Personnel sign confidentiality undertakings and acknowledge the security policies and code of conduct before access, complete security and privacy awareness training at least annually (phishing, data handling, applicable privacy law, incident reporting) and re-acknowledge the policies annually; compliance is part of performance review.
5.3 Offboarding. Access is removed promptly on role change and within one (1) business day of termination; company-managed devices are returned and securely erased before reuse or disposal (Section 17.3).
5.4 Personnel location. Datafold Personnel access Customer Data remotely from where they work, subject to Sections 6 and 17; location restrictions apply only where the Order Form or Statement of Work states one, and the DPA states how Customer may learn the countries concerned.
6. Access control
6.1 Least privilege and reviews. Access to production systems and Customer Data is role-based and least-privilege, granted on documented approval to Datafold Personnel with a business need, reviewed at least quarterly and on role change, and removed when no longer required; exceptions need security-council approval.
6.2 Authentication. Privileged and production access requires multi-factor authentication or single sign-on with MFA; root accounts are MFA-protected and monitored; administrative access to production control planes Datafold operates is encrypted over a VPN or equivalent private path.
6.3 Unique credentials; Platform-held secrets. Datafold Personnel use unique accounts; shared credentials are prohibited. Credentials the Platform uses to reach Customer's systems are encrypted at the application layer before storage, kept out of source control and logs, and accessible only to the components that need them; the key sits in the Platform's protected runtime configuration, apart from the data, under Datafold's cryptography and access-control policies.
6.4 Customer authentication. The Platform supports single sign-on through SAML 2.0 and OAuth-based identity providers and local accounts with password length and complexity rules, as Customer configures (Section 20); local credentials are stored as salted hashes and API keys can be revoked.
7. Encryption and key management
7.1 At rest. Where Section 4.4 allocates encryption at rest to Datafold, Customer Data stored by the Platform is encrypted with AES-256 or stronger under keys in the cloud provider's key management service; volumes, databases, object storage and backups are encrypted by default and by policy; Platform-held credentials are additionally encrypted at the application layer (Section 6.3).
7.2 In transit. Customer Data in transit between Customer's users or systems and the Platform, and between the Platform and Model Providers, is encrypted using TLS 1.2 or higher; Datafold enforces modern cipher suites on its load balancers and disables legacy protocols. Connectivity to Customer's systems uses the encrypted method Customer selects (Section 4.5(c)).
7.3 Keys. Provider-managed keys rotate under the provider's managed rotation and Datafold's cryptography policy; application-layer keys and credentials are rotated on suspected compromise; key access is restricted to named roles and logged. Key custody for Platform data stores, and customer-managed keys where available, are as Section 4.4 (row 3) and the Order Form or Statement of Work provide.
8. Network security and tenant segregation
8.1 Production workloads Datafold hosts run in private subnets without direct inbound internet access, behind managed load balancers, on provider-managed Kubernetes, with segmentation and private endpoints between components; access between components is restricted to what is required, and network rules are reviewed on change and at least annually. In Single Tenant Customer-hosted deployments the Platform runs on the compute platform Customer provides, inside Customer's network controls, with the segmentation between Platform components that the deployment guide specifies.
8.2 Where Section 4.3 identifies the elected Deployment Model as multi-tenant, Customer Data is logically segregated by tenant: an organization identifier on Customer Data records is checked by the Platform's application logic on access, so only the authenticated tenant's Customer Data is reachable.
8.3 Where Section 4.4 allocates edge protection to Datafold, the Platform ingress is protected against volumetric denial-of-service attacks by the cloud provider's edge protection.
9. Logging and monitoring
9.1 Production infrastructure and the Platform log authentication events, privileged actions, configuration changes, faults and application errors. Logging is designed not to record Customer Data values; error logs may contain query-text fragments and identifiers, protected as Customer Data and deleted on the Section 9.3 rotation.
9.2 Logs are centralized, tamper-protected and monitored through cloud-native threat detection and a central monitoring platform alerting on-call personnel to anomalous privileged and root activity, configuration drift and unusual data egress.
9.3 Where Section 4.4 allocates log retention to Datafold, logs of the multi-tenant Deployment Model, and of a deployment dedicated to Customer that Datafold operates, are retained at least twelve (12) and at most thirteen (13) months and then deleted, unless the Order Form or Statement of Work states a different period for a dedicated deployment; otherwise Customer's configuration applies. Customer Data fragments in logs are used only for security investigation and troubleshooting.
10. Vulnerability and patch management
10.1 Datafold scans dependencies and container images continuously and cloud configuration against recognized benchmarks; findings are triaged by CVSS severity and exploitability, tracked in a ticketing system and remediated in Datafold-operated environments within these targets: Critical, seven (7) days; High, fourteen (14) days; Medium, thirty (30) days; Low, ninety (90) days; where a fix is unavailable or disruptive, compensating controls are applied and the exception documented.
10.2 External vulnerability scans of the Datafold-operated production environment run at least quarterly and internal scans against production-mirroring environments; operating-system and platform patches are applied through the cloud provider's managed update mechanisms within the Section 10.1 period for the severity addressed.
10.3 Datafold informs Customer, through the Trust Portal or directly, of a confirmed Critical or High vulnerability affecting the Services that remains unremediated beyond the Section 10.1 period, with compensating controls and the expected date. In every Deployment Model Datafold publishes Platform releases containing security fixes, identifies those for Critical or High vulnerabilities, and notifies Customer without undue delay of a Critical Platform vulnerability requiring action by the party operating the deployment; the party Section 4.4 allocates their application to applies them.
11. Secure development lifecycle
11.1 Datafold follows a documented secure development lifecycle: mandatory peer review before merge; automated tests, dependency and image scanning and automated security screening of every pull request in continuous integration; versioned images; separate development, staging and production environments with distinct credentials; design review and security testing, before release, of changes to authentication and other security controls; and, in every Deployment Model, the Platform's role and permission model.
11.2 Datafold does not copy Customer Data into non-production environments; any exception requires documented executive approval, minimization where feasible and the production standard. Customer source code held in Datafold-controlled repositories for Professional Services is subject to Section 6 access controls and Section 9 logging and is deleted as Section 14.3 provides.
11.3 Production changes follow a documented change-management process with peer review, testing, approval and rollback (emergency changes documented and reviewed after the fact); infrastructure is defined as code and deployed through controlled pipelines; secure baseline configurations aligned to recognized benchmarks are maintained, with deviations detected by automated configuration monitoring.
12. Penetration testing
12.1 An independent third party tests, at least annually, the production application and exposed infrastructure of the Deployment Model that Section 4.3 identifies as within Datafold's attestation; findings are remediated within the Section 10.1 periods and tracked to closure, Critical and High findings being retested before closure.
12.2 The most recent penetration test report and its remediation status are available on the Trust Portal under confidentiality obligations.
12.3 Customer may test the deployment Datafold operates for it at a frequency, on notice and under rules of engagement agreed in writing, will share the results, and Datafold remediates confirmed findings under Section 10.1; testing of infrastructure Section 4.4 allocates to Customer is Customer's own affair, subject to the Agreement.
12.4 Datafold maintains a responsible-disclosure channel at the address for security notices stated in the Order Form for reports from security researchers.
13. Business continuity and disaster recovery
13.1 Datafold maintains a documented business continuity and disaster recovery plan covering extended outages of business-critical systems, including the Platform, with assigned roles, reviewed and tested at least annually with issues tracked to resolution.
13.2 Production deployments that Datafold operates are monitored for capacity, latency and error rates with alerting on degradation, and its data stores are backed up as Section 14 provides.
13.3 Where Section 4.4 allocates disaster recovery to Datafold, the recovery point objective is twenty-four (24) hours and the recovery time objective eight (8) hours for loss of the primary region, unless the Order Form states otherwise, and the procedure, including restoration from backup, is tested at least annually; in every Deployment Model Datafold provides Platform redeployment support after loss of the infrastructure.
14. Backups and data retention
14.1 Where Section 4.4 allocates backups to Datafold, Platform data stores are backed up at least daily, encrypted at rest and in transit, with copies sent promptly to a second region or in the Order Form or Statement of Work; where it allocates backups to Customer, they stay in Customer's account, any Datafold key arrangement being as Section 4.5(b) provides.
14.2 Primary-database backups are retained for a rolling seven (7) days and other Platform backups for no longer than thirty-five (35) days; backups are then overwritten or deleted, and restoration is tested at least annually.
14.3 Customer Data held in the Platform is exported and deleted within the periods the DPA states, which also governs backups pending rotation and deletion certificates; protected health information follows the applicable Business Associate Agreement; extracts, comparison results and row-level examples made under a Statement of Work are retained and deleted as the DPA and the Statement of Work provide.
14.4 Working data and retained results. The Platform retains, in the application database of the elected Deployment Model, comparison statistics and a bounded set of row-level examples of differences: at most one thousand (1,000) rows of differing values per comparison, with long values truncated, and at most five hundred (500) rows each of exclusive and duplicate primary keys, for the periods the DPA states. Temporary tables the Platform creates in Customer's systems are scheduled for deletion no later than seventy-two (72) hours after the run and dropped by the Platform's cleanup process, and Customer may drop them at any time; working data transferred for a comparison that cannot run by hash is deleted when the comparison completes.
15. Subprocessor and vendor governance
15.1 Datafold assesses vendors before engagement by a risk rating (access level, data sensitivity, operational impact), reviews them at least annually (security assessment, SOC 2 or equivalent report, or continuous monitoring, by rating) and tracks corrective actions; vendors that may access Customer Data are bound by written terms as the DPA provides for Subprocessors, and new vendor contracts are approved by executive management.
15.2 The Subprocessors that process Customer Data, their documented processing locations, and the Datafold-Managed Model Providers with links to their standard commercial terms are published on the Subprocessor List, through which notice of new or replacement Subprocessors and Model Providers is given as the DPA provides.
16. AI Features data handling
16.1 AI Features are optional and can be enabled or disabled by Customer's administrators, where the Platform permits, or in the Order Form or Statement of Work, except AI Features a Statement of Work relies on, as the Agreement provides; when enabled, Inputs (source code, schemas, metadata, queries, error output and, where configured, limited data samples) go to a Customer-Provided Model Endpoint where Customer has elected one under the Agreement or, otherwise, to one or more Datafold-Managed Model Providers that Datafold selects, alone or in combination, from the Subprocessor List.
16.2 Datafold-Managed Model Providers, which Datafold selects and contracts with in every Deployment Model, process Inputs and Outputs under their own standard commercial terms, linked on the Subprocessor List; Datafold's commitments regarding them, the Customer-Provided Model Endpoint alternative and Datafold's own no-training commitment are in the Agreement and the DPA. A model trained or tuned for Customer alone requires Customer's written opt-in recorded in the Statement of Work.
16.3 Customer controls what the Platform accesses and transmits. For Customer's own use of the Platform, the recommended control is an OAuth connection to the data warehouse, under which the Platform runs with the connecting user's own database permissions, including any masking and row- or column-level restrictions the warehouse applies, so that the Platform sees only what that user may see; Customer may also exclude columns from comparison; each as the Documentation describes. For Professional Services, Datafold Personnel access what Customer grants them access to, and Customer controls that access (Section 20.1(c)). For a Deployment Model that Section 4.3 identifies as hosted in Customer's environment, and for deployments designated for protected health information under a Business Associate Agreement, Datafold recommends a Customer-Provided Model Endpoint within Customer's cloud account so that Inputs do not leave Customer's environment.
16.4 Datafold's internal AI usage policy allows Datafold Personnel to use with Customer Data only approved AI tooling provisioned through Datafold's accounts, bans consumer, free-tier and personal AI services, and bans submitting Customer Data to a public AI service or any system in which prompts may be used for training, save where the data is anonymized, the system runs in Datafold's or Customer's cloud account with security-council approval, or Customer has contracted for AI Features; under Partner-Access (Section 4.2), only the tooling Customer or the partner authorizes is used where it so requires.
17. Physical security and endpoints
17.1 Datafold operates no data centers; the deployments it hosts run on the infrastructure Subprocessors on the Subprocessor List, each holding SOC 2 and ISO/IEC 27001 attestations covering physical and environmental controls, reviewed before first use and annually. Where Section 4.4 allocates physical security to Customer, it is Customer's cloud provider's.
17.2 Datafold is remote-first and holds no Customer Data on paper or removable media. Customer Data is accessed only from company-managed endpoints or devices issued under Partner-Access (Section 4.2), never personal devices; company-managed endpoints with Customer Data access are encrypted at rest, enrolled in device management and, by policy, screen-locked, patched and full-disk encrypted. Datafold is responsible in every Deployment Model for Datafold Personnel, Datafold-managed devices and Datafold-issued credentials.
17.3 Datafold inventories production systems and company-managed endpoints under its asset-management policy; media and endpoints are securely erased before reuse or securely destroyed at disposal under its data-management policy.
18. Incident response
18.1 Datafold maintains a documented incident response plan (roles, escalation, severity classification, containment, eradication, recovery, evidence preservation, communications), reviewed and approved by management at least annually.
18.2 Security alerts are routed 24x7 to on-call personnel and escalated under the plan's severity classification; whether an event is a Security Incident, and when it is Confirmed, follows the DPA's definitions of Security Incident, Confirmation and Confirmed Incident.
18.3 Datafold notifies Customer of a Confirmed Incident within the period, at the contacts, with the information and in the phases that the Agreement and the DPA provide, gives preliminary notice before Confirmation where an Order Form or SOW so provides, and after resolution documents root cause and corrective actions.
18.4 Security notices to Datafold, including reports of suspected compromise of Customer's credentials or environment, go to the address for security notices stated in the Order Form.
19. Attestations, evidence and customer assurance
19.1 Datafold maintains a SOC 2 Type II attestation (Security, Availability and Confidentiality), examined annually by an independent CPA firm and covering the production environment of the Deployment Model that Section 4.3 identifies as within scope and the processes used to operate it, or a successor attestation of equivalent scope, during the term of the Agreement. The Trust Portal states the environments and period covered by the current report; infrastructure Section 4.4 allocates to Customer is outside it.
19.2 Datafold's controls map to the HIPAA Security Rule safeguards for deployments designated for protected health information under a Business Associate Agreement, and its practices are designed to support customers' obligations under GDPR, UK GDPR and US state privacy laws. Datafold holds no ISO/IEC 27001, PCI DSS, HITRUST or FedRAMP certification, and no HIPAA or GDPR certification exists.
19.3 Evidence. The evidence listed on the Trust Portal is available there under confidentiality obligations. Datafold answers reasonable written security questionnaires as the DPA provides.
20. Customer responsibilities
20.1 In every Deployment Model Customer is responsible for: (a) the controls Section 4.4 allocates to Customer, including the security, availability, patching, monitoring and cost of the cloud account, network, cluster or servers, storage and identity provider it operates; (b) under Partner-Access, what it or a partner issues (Section 4.2); (c) what data, including Sensitive Data, it exposes to the Services and Datafold Personnel, the access it configures accordingly, and any agreement applicable law requires before exposing regulated data (as the DPA provides); (d) detecting incidents in its own environment, cloud account, identity provider and source and target systems, and promptly notifying Datafold at the address for security notices stated in the Order Form of suspected compromise of its credentials, environment or user accounts affecting the Platform; and (e) keeping its security and privacy contacts current in the Order Form, Statement of Work or Platform settings.
21. Contact
Security and privacy inquiries: the address for security notices stated in the Order Form. Trust Portal: https://security.datafold.com (the "Trust Portal" referred to in the Agreement and the DPA).