Conductor logo
Conductor
Enterprise and security

Conductor enterprise security, SSO, SOC 2, RBAC, and procurement

A procurement review of Conductor's SOC 2 Type II, ISO 27001 and ISO 42001, SAML SSO, plan-gated RBAC, encryption, recovery, legal terms, audit logs, and data-residency uncertainty.

Trakkr editorial teamPublished 2026-08-25
10 min read
Last updated: August 25, 2026

Quick answer

Does Conductor meet enterprise security, identity, legal, and procurement requirements?

Conductor presents a strong public procurement case: ISO 27001, ISO 42001, SOC 2 Type II, SAML SSO, role-based access, encryption, recovery objectives, regional service agreements, and a 99.5 percent availability SLA. Growth includes SSO, while Enterprise adds custom RBAC. Two items need written proof: public material describes internal security logging but not a customer audit-log export, and it does not expose a selectable data-residency matrix.

Published by Trakkr. Sources checked 2026-08-25.
Evidence: Conductor Security Center, Conductor plans and capabilities, Conductor enterprise platform, Conductor Privacy Policy, Conductor Service Agreement index, Conductor Service Level AgreementNot publicly verified. The Security Center confirms vendor-side logging and audit controls, not an in-product customer audit trail or export. Buyers should ask what tenant activity is visible and retainable.Not publicly verified. The privacy policy describes international transfers and Standard Contractual Clauses, while detailed residency information is not exposed on the public Security Center page.
Certifications
ISO 27001, ISO 42001, and SOC 2 Type IIEvidence: Conductor Security Center
Single sign-on
SAML SSO on Growth and Enterprise; not included on EssentialsEvidence: Conductor Security Center, Conductor plans and capabilities
Permissions
Custom enterprise RBAC is gated to EnterpriseEvidence: Conductor enterprise platform, Conductor plans and capabilities, Conductor Security Center
Recovery
24-hour RTO and less-than-one-hour RPO publishedEvidence: Conductor Security Center, Conductor Privacy Policy
Availability
99.5 percent quarterly platform availability in the public SLAEvidence: Conductor Service Agreement index, Conductor Service Level Agreement
Open evidence
Customer-facing audit export and selectable residency regions are not publicly documentedEvidence: Conductor Security Center, Conductor plans and capabilities, Conductor Privacy PolicyNot publicly verified. The Security Center confirms vendor-side logging and audit controls, not an in-product customer audit trail or export. Buyers should ask what tenant activity is visible and retainable.Not publicly verified. The privacy policy describes international transfers and Standard Contractual Clauses, while detailed residency information is not exposed on the public Security Center page.

Conductor enterprise procurement evidence

Conductor enterprise procurement evidence
ControlConductor public evidencePlan or contract signalProcurement action
Independent assuranceSOC 2 Type II, ISO 27001, and ISO 42001 listedReports and architecture documents are gatedRequest current scope, report periods, exceptions, bridge coverage, and remediation evidenceEvidence: Conductor Security Center
IdentitySAML SSO plus password login with optional two-factor authenticationSSO begins on GrowthTest IdP setup, enforced MFA, session controls, deprovisioning, and break-glass accessEvidence: Conductor Security Center, Conductor plans and capabilities
AuthorizationCustom role-based permissions and cross-account configurationsEnterprise Permissions or RBAC is Enterprise-onlyMap roles to brands, regions, reports, exports, prompts, API keys, and administrative actionsEvidence: Conductor enterprise platform, Conductor plans and capabilities, Conductor Security Center
Audit evidenceVendor-side infrastructure, application, database, and security logs are centralizedSecurity Center says logs are not shared externallyRequire a demonstration of tenant activity history, export, retention, and admin eventsEvidence: Conductor Security Center, Conductor plans and capabilitiesNot publicly verified. The Security Center confirms vendor-side logging and audit controls, not an in-product customer audit trail or export. Buyers should ask what tenant activity is visible and retainable.
Data locationPrivacy terms cover international transfers and safeguardsNo public selectable residency matrixPut primary storage, backups, logs, support access, subprocessors, and disaster recovery locations in writingEvidence: Conductor Security Center, Conductor Privacy PolicyNot publicly verified. The privacy policy describes international transfers and Standard Contractual Clauses, while detailed residency information is not exposed on the public Security Center page.
Resilience and termsEncrypted backups, 24-hour RTO, sub-one-hour RPO, regional agreements, and 99.5 percent SLADetailed documents and negotiated terms may varyReview exclusions, service credits, incident notice, restoration tests, deletion, and renewal termsEvidence: Conductor Security Center, Conductor Privacy Policy, Conductor Service Agreement index, Conductor Service Level Agreement

This is a review of public evidence, not a certification, penetration test, legal opinion, or substitute for Conductor's gated reports and negotiated order form.

Which Conductor certifications can procurement verify?

The Security Center lists ISO 27001, ISO 42001, and SOC 2 Type II and provides a gated request path for certification documents, the SOC report, architecture diagram, penetration-test attestation, and CAIQ Lite.

Ask for the legal entity, products, locations, control period, subservice organizations, exceptions, bridge letter, and current certificate validity. Public badges alone do not establish that every purchased module is in scope.

Evidence: Conductor Security Center

What do SSO and role-based access look like by plan?

Conductor documents SAML SSO and places it on Growth and Enterprise. The current pricing table reserves Enterprise Permissions or RBAC for Enterprise, while the enterprise page describes custom permission-based roles across complex organizations.

Buyers on Growth should not infer enterprise-grade custom authorization from having SSO. Test the exact role matrix, brand boundaries, export permissions, prompt approvals, and API access required.

Evidence: Conductor Security Center, Conductor plans and capabilities, Conductor enterprise platform

Can customers export Conductor audit logs for their SIEM or control testing?

The Security Center says Conductor centrally collects and analyzes infrastructure, application, database, and security logs, and that those vendor security logs are not shared externally.

We did not find a public customer activity-log export contract. Procurement should ask for in-product tenant events, actor and IP fields, API and MCP activity, retention, export, SIEM delivery, and access-review evidence.

Evidence: Conductor Security Center, Conductor plans and capabilitiesNot publicly verified. The Security Center confirms vendor-side logging and audit controls, not an in-product customer audit trail or export. Buyers should ask what tenant activity is visible and retainable.

What do data residency and legal terms look like?

What resilience and availability commitments are public?

Conductor publishes encrypted backups, a 24-hour recovery-time objective, a recovery-point objective under one hour, and a public quarterly platform-availability standard of at least 99.5 percent.

Review the SLA definition, maintenance exclusions, service-credit remedy, disaster-recovery test evidence, backup retention, restoration scope, and incident-notice terms before treating those figures as a complete resilience package.

Evidence: Conductor Security Center, Conductor Privacy Policy, Conductor Service Agreement index, Conductor Service Level Agreement

Evidence and method

The assurance stack is concrete

Conductor names three current certifications and exposes a gated route for the reports and architecture evidence a security team needs.

Evidence: Conductor Security Center

Identity and authorization gates are public

Pricing distinguishes Growth SSO from Enterprise RBAC, preventing buyers from assuming every access control is included on each plan.

Evidence: Conductor Security Center, Conductor plans and capabilities, Conductor enterprise platform

Recovery objectives are quantified

The Security Center publishes an RTO, RPO, backup approach, and access-control posture rather than only a general security statement.

Evidence: Conductor Security Center, Conductor Privacy Policy

Audit and residency remain due-diligence items

Public sources confirm vendor logging and international safeguards but do not establish tenant log export or selectable customer data regions.

Evidence: Conductor Security Center, Conductor plans and capabilities, Conductor Privacy PolicyNot publicly verified. The Security Center confirms vendor-side logging and audit controls, not an in-product customer audit trail or export. Buyers should ask what tenant activity is visible and retainable.Not publicly verified. The privacy policy describes international transfers and Standard Contractual Clauses, while detailed residency information is not exposed on the public Security Center page.

How we checked this page

We separated independent assurance, authentication, authorization, tenant audit evidence, encryption, recovery, residency, legal jurisdiction, and service availability so one certification badge did not answer every procurement question.

  1. 1. Checked the current Security Center, pricing, enterprise, privacy, service-agreement, and SLA pages and recorded plan gates exactly as published.
  2. 2. Marked audit export and selectable residency as not publicly verified because vendor-side logging and transfer safeguards do not prove those customer controls.
  3. 3. Compared Trakkr only from its current official security and pricing pages, including its explicit statement about vendor-level SOC 2 status.
  • Limitation: We did not receive gated reports, test SSO or roles, review a DPA or subprocessor annex, complete a questionnaire, or inspect a negotiated order form.
  • Limitation: Conductor may provide stronger private commitments or customer controls than its public pages expose; those claims need written evidence during procurement.

When is Conductor or Trakkr the better procurement fit?

Conductor is the stronger documented choice when procurement requires a vendor's current SOC 2 Type II, ISO 27001, ISO 42001, SAML SSO, enterprise RBAC, quantified recovery objectives, and gated assurance reports.

Trakkr publishes strong encryption, isolation, RBAC, MFA, regional infrastructure, and Enterprise SSO or SCIM, but its own security page says it does not currently hold its own SOC 2. Choose Trakkr only when that assurance gap is acceptable and focused AI visibility, faster setup, or clearer integration entitlement matters more. Require written residency and tenant audit evidence from either vendor when those controls are mandatory.

Evidence: Conductor Security Center, Conductor plans and capabilities, Conductor enterprise platform, Conductor Privacy Policy, Security at Trakkr, Trakkr pricing and plan comparisonNot publicly verified. The Security Center confirms vendor-side logging and audit controls, not an in-product customer audit trail or export. Buyers should ask what tenant activity is visible and retainable.Not publicly verified. The privacy policy describes international transfers and Standard Contractual Clauses, while detailed residency information is not exposed on the public Security Center page.

Conductor's current Security Center lists SOC 2 Type II and offers gated access to the report. Buyers should review scope, period, exceptions, and bridge coverage.

See how AI talks about your brand

Enter your domain to get a free AI visibility report in under 60 seconds.

14-day trialCancel anytime60 second setup