Conductor enterprise security, SSO, SOC 2, RBAC, and procurement
A procurement review of Conductor's SOC 2 Type II, ISO 27001 and ISO 42001, SAML SSO, plan-gated RBAC, encryption, recovery, legal terms, audit logs, and data-residency uncertainty.
Quick answer
Does Conductor meet enterprise security, identity, legal, and procurement requirements?
Conductor presents a strong public procurement case: ISO 27001, ISO 42001, SOC 2 Type II, SAML SSO, role-based access, encryption, recovery objectives, regional service agreements, and a 99.5 percent availability SLA. Growth includes SSO, while Enterprise adds custom RBAC. Two items need written proof: public material describes internal security logging but not a customer audit-log export, and it does not expose a selectable data-residency matrix.
Key facts and evidence
- Certifications
- ISO 27001, ISO 42001, and SOC 2 Type IIEvidence: Conductor Security Center
- Single sign-on
- SAML SSO on Growth and Enterprise; not included on EssentialsEvidence: Conductor Security Center, Conductor plans and capabilities
- Permissions
- Custom enterprise RBAC is gated to EnterpriseEvidence: Conductor enterprise platform, Conductor plans and capabilities, Conductor Security Center
- Recovery
- 24-hour RTO and less-than-one-hour RPO publishedEvidence: Conductor Security Center, Conductor Privacy Policy
- Availability
- 99.5 percent quarterly platform availability in the public SLAEvidence: Conductor Service Agreement index, Conductor Service Level Agreement
- Open evidence
- Customer-facing audit export and selectable residency regions are not publicly documentedEvidence: Conductor Security Center, Conductor plans and capabilities, Conductor Privacy PolicyNot publicly verified. The Security Center confirms vendor-side logging and audit controls, not an in-product customer audit trail or export. Buyers should ask what tenant activity is visible and retainable.Not publicly verified. The privacy policy describes international transfers and Standard Contractual Clauses, while detailed residency information is not exposed on the public Security Center page.
Conductor enterprise procurement evidence
| Control | Conductor public evidence | Plan or contract signal | Procurement action |
|---|---|---|---|
| Independent assurance | SOC 2 Type II, ISO 27001, and ISO 42001 listed | Reports and architecture documents are gated | Request current scope, report periods, exceptions, bridge coverage, and remediation evidenceEvidence: Conductor Security Center |
| Identity | SAML SSO plus password login with optional two-factor authentication | SSO begins on Growth | Test IdP setup, enforced MFA, session controls, deprovisioning, and break-glass accessEvidence: Conductor Security Center, Conductor plans and capabilities |
| Authorization | Custom role-based permissions and cross-account configurations | Enterprise Permissions or RBAC is Enterprise-only | Map roles to brands, regions, reports, exports, prompts, API keys, and administrative actionsEvidence: Conductor enterprise platform, Conductor plans and capabilities, Conductor Security Center |
| Audit evidence | Vendor-side infrastructure, application, database, and security logs are centralized | Security Center says logs are not shared externally | Require a demonstration of tenant activity history, export, retention, and admin eventsEvidence: Conductor Security Center, Conductor plans and capabilitiesNot publicly verified. The Security Center confirms vendor-side logging and audit controls, not an in-product customer audit trail or export. Buyers should ask what tenant activity is visible and retainable. |
| Data location | Privacy terms cover international transfers and safeguards | No public selectable residency matrix | Put primary storage, backups, logs, support access, subprocessors, and disaster recovery locations in writingEvidence: Conductor Security Center, Conductor Privacy PolicyNot publicly verified. The privacy policy describes international transfers and Standard Contractual Clauses, while detailed residency information is not exposed on the public Security Center page. |
| Resilience and terms | Encrypted backups, 24-hour RTO, sub-one-hour RPO, regional agreements, and 99.5 percent SLA | Detailed documents and negotiated terms may vary | Review exclusions, service credits, incident notice, restoration tests, deletion, and renewal termsEvidence: Conductor Security Center, Conductor Privacy Policy, Conductor Service Agreement index, Conductor Service Level Agreement |
This is a review of public evidence, not a certification, penetration test, legal opinion, or substitute for Conductor's gated reports and negotiated order form.
Which Conductor certifications can procurement verify?
The Security Center lists ISO 27001, ISO 42001, and SOC 2 Type II and provides a gated request path for certification documents, the SOC report, architecture diagram, penetration-test attestation, and CAIQ Lite.
Ask for the legal entity, products, locations, control period, subservice organizations, exceptions, bridge letter, and current certificate validity. Public badges alone do not establish that every purchased module is in scope.
What do SSO and role-based access look like by plan?
Conductor documents SAML SSO and places it on Growth and Enterprise. The current pricing table reserves Enterprise Permissions or RBAC for Enterprise, while the enterprise page describes custom permission-based roles across complex organizations.
Buyers on Growth should not infer enterprise-grade custom authorization from having SSO. Test the exact role matrix, brand boundaries, export permissions, prompt approvals, and API access required.
Can customers export Conductor audit logs for their SIEM or control testing?
The Security Center says Conductor centrally collects and analyzes infrastructure, application, database, and security logs, and that those vendor security logs are not shared externally.
We did not find a public customer activity-log export contract. Procurement should ask for in-product tenant events, actor and IP fields, API and MCP activity, retention, export, SIEM delivery, and access-review evidence.
What do data residency and legal terms look like?
Conductor's Privacy Policy describes international transfers and Standard Contractual Clauses. Its Service Agreement index routes buyers to different terms for the United States, DACH, wider EMEA, the United Kingdom, and other markets.
The public Security Center names data residency as a control area but does not expose selectable regions. Require a written data-flow and residency schedule if storage or support access must remain in a named jurisdiction.
What resilience and availability commitments are public?
Conductor publishes encrypted backups, a 24-hour recovery-time objective, a recovery-point objective under one hour, and a public quarterly platform-availability standard of at least 99.5 percent.
Review the SLA definition, maintenance exclusions, service-credit remedy, disaster-recovery test evidence, backup retention, restoration scope, and incident-notice terms before treating those figures as a complete resilience package.
Evidence and method
The assurance stack is concrete
Conductor names three current certifications and exposes a gated route for the reports and architecture evidence a security team needs.
Evidence: Conductor Security CenterIdentity and authorization gates are public
Pricing distinguishes Growth SSO from Enterprise RBAC, preventing buyers from assuming every access control is included on each plan.
Evidence: Conductor Security Center, Conductor plans and capabilities, Conductor enterprise platformRecovery objectives are quantified
The Security Center publishes an RTO, RPO, backup approach, and access-control posture rather than only a general security statement.
Evidence: Conductor Security Center, Conductor Privacy PolicyAudit and residency remain due-diligence items
Public sources confirm vendor logging and international safeguards but do not establish tenant log export or selectable customer data regions.
Evidence: Conductor Security Center, Conductor plans and capabilities, Conductor Privacy PolicyNot publicly verified. The Security Center confirms vendor-side logging and audit controls, not an in-product customer audit trail or export. Buyers should ask what tenant activity is visible and retainable.Not publicly verified. The privacy policy describes international transfers and Standard Contractual Clauses, while detailed residency information is not exposed on the public Security Center page.How we checked this page
We separated independent assurance, authentication, authorization, tenant audit evidence, encryption, recovery, residency, legal jurisdiction, and service availability so one certification badge did not answer every procurement question.
- 1. Checked the current Security Center, pricing, enterprise, privacy, service-agreement, and SLA pages and recorded plan gates exactly as published.
- 2. Marked audit export and selectable residency as not publicly verified because vendor-side logging and transfer safeguards do not prove those customer controls.
- 3. Compared Trakkr only from its current official security and pricing pages, including its explicit statement about vendor-level SOC 2 status.
- Limitation: We did not receive gated reports, test SSO or roles, review a DPA or subprocessor annex, complete a questionnaire, or inspect a negotiated order form.
- Limitation: Conductor may provide stronger private commitments or customer controls than its public pages expose; those claims need written evidence during procurement.
When is Conductor or Trakkr the better procurement fit?
Conductor is the stronger documented choice when procurement requires a vendor's current SOC 2 Type II, ISO 27001, ISO 42001, SAML SSO, enterprise RBAC, quantified recovery objectives, and gated assurance reports.
Trakkr publishes strong encryption, isolation, RBAC, MFA, regional infrastructure, and Enterprise SSO or SCIM, but its own security page says it does not currently hold its own SOC 2. Choose Trakkr only when that assurance gap is acceptable and focused AI visibility, faster setup, or clearer integration entitlement matters more. Require written residency and tenant audit evidence from either vendor when those controls are mandatory.
Conductor's current Security Center lists SOC 2 Type II and offers gated access to the report. Buyers should review scope, period, exceptions, and bridge coverage.
Yes. Conductor documents SAML SSO and the current pricing table includes it on Growth and Enterprise, but not Essentials.
No. Current pricing marks Enterprise Permissions or RBAC as included on Enterprise and not included on Essentials or Growth.
Those exact controls are not publicly established. Conductor documents internal logging and international-transfer safeguards, but buyers should request tenant log and residency commitments in writing.
Sources and related reading
See how AI talks about your brand
Enter your domain to get a free AI visibility report in under 60 seconds.