About

Data Security

Protecting your marketing data is our #1 priority.

At IWCO, we understand the challenges Chief Marketing Officers (CMOs) and business leaders face with evolving regulatory needs, changing markets, and data protection requirements.

 

That’s why IWCO goes beyond the baseline to deliver a best-in-class information security program, with considerations for clients in highly regulated industries like Finance, Healthcare, Insurance, and others.

Why choose IWCO as your marketing partner?

trust icon
Confidence and Trust:

Rest assured — your data is in secure hands. IWCO’s Information Security Program is independently audited multiple times annually.

certification icon
Industry-Leading Certifications:

We hold ISO 27001, PCI DSS v4.0, and HITRUST CSF r2 certifications, are SOC 2 compliant, and operate HIPAA/HITECH compliant facilities.

security icon
Comprehensive Security Measures:

Our security practices may start with compliance, but IWCO also leverages a risk-based, defense-in-depth approach to Information Security that includes employee training, robust data protection policies, and integration of clients’ data security requirements into our processes.

IWCO Information Security Foundations & Compliance

IWCO has based its security practice on ISO 27001, PCI DSS (Payment Card Industry), and HITRUST (Health Information Trust Alliance) standards to promote the development of a corporate environment which safeguards the security, confidentiality, privacy, integrity, and availability of customer and company information.
 
We are independently certified to all three standards by a qualified third-party assessor. Additionally, IWCO undergoes annual SOC 2 Type II assessment and reporting for all 5 trust service criteria.
 
In order to achieve certification, we were required to meet or exceed established benchmarks relating to the physical facilities, information technology, and internal process controls of our data security system.

Organization of Information Security

Our dedicated information security personnel are focused on the areas of governance, risk and compliance, internal audit, security incident response, training, and vulnerability management.
 
IWCO’s security program is fully supported by a Security Steering Committee, composed of members of senior leadership to ensure oversight and administration of the Information Security Management System (ISMS).
 
Staff certifications include CC, CISM, CISA, SSCP, Security+, and ISO 27001 Lead Auditor.

IWCO CERTIFICATIONS

HIPAA Compliance Icon
ISO 270001 Certified Icon
PCI Security Standards Council

IWCO maintains a PCI DSS Level 1 certification

AICPA SOC certification

IWCO maintains a SOC2 Type II report, including all 5 applicable trust service criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy

r2 Risk-Based 2 Year HitTrust Certified

IWCO maintains HITRUST r2 Certification, the most rigorous and comprehensive certification level

Our Culture of Security

We’ve fostered a culture of security and recognize that it is a continuously evolving practice.

 

Security begins on the first day of employment, with new employees receiving security awareness and critical compliance training. Our internal security requirements are seamlessly integrated with those of our clients into our Employee Handbook, data security policies, and everyday procedures.

 

We continue to build security awareness into our company culture with ongoing communication across the organization to ensure everyone understands that security is part of everyone’s job, with discipline and diligence required at all times.

We Can Help. Let's Talk!

Contact us today to learn more about how we can deliver innovative, creative, and data-driven solutions that drive measurable results for your unique business.