This page describes the controls in place for the TryEntitle website and early sales process. Client delivery environments are scoped per engagement.

Data in transit and at rest

  • The website (tryentitle.com) is served over HTTPS/TLS through our hosting provider.
  • Booking data submitted through our scheduling tool is sent over TLS and stored in that provider’s systems under its security controls.
  • We do not store client production databases on the marketing website. Engagement workspaces and document stores are set up per client and documented in that engagement’s paperwork.

Access control

  • Access to business systems used for sales and delivery is limited to people who need it for their role.
  • Access is revoked when a person leaves the engagement or the company.
  • Multi-factor authentication is enabled on TryEntitle-controlled accounts that hold client or prospect data, wherever the provider supports it.
  • We avoid shared credentials for client systems. Where a client requires one, it is a temporary exception and is rotated or revoked when no longer needed.

Subprocessors

Subprocessor typeRole
Scheduling providerScheduling and booking
Website hosting providerWebsite hosting and content delivery

This list matches the Privacy Policy and Annex 2 of the Data Processing Agreement. Additional subprocessors for a paid engagement are disclosed in that engagement’s DPA annex.

Human review and handling

Our services often keep a person in the loop for exceptions and judgment calls. For client work:

  • Working documents are stored only in systems agreed for that engagement.
  • Exception review is done by named TryEntitle personnel (or client-named reviewers), with access limited to what the workflow requires.
  • Working data is kept only as long as the engagement and DPA allow, then deleted or returned.

The marketing site does not host client case files.

Vulnerability reporting

If you believe you have found a security issue affecting tryentitle.com or a TryEntitle-operated system, email security@tryentitle.com with enough detail to reproduce it. We will acknowledge reports within 5 business days and keep you updated as we investigate.

Please do not access data that isn’t yours or degrade the availability of our services while testing.

Incident response

If we become aware of a personal data breach affecting client personal data we process, we will notify the affected client without undue delay and, where feasible, within 72 hours, consistent with our Data Processing Agreement. Notice will include the facts then known and the steps we are taking, with updates as the investigation develops.

Contact

Security reports: security@tryentitle.com
Privacy requests: privacy@tryentitle.com
General inquiries: hello@tryentitle.com