Security at Support Fusion
Support Fusion is ISO 27001 certified. For IT service providers working with regulated enterprise clients, security posture is part of every procurement conversation. Ours is independently audited and continuously monitored.
How we protect your data
Security built into the platform from the ground up, not bolted on after the fact.
No credential storage
Credentials are never hardcoded or stored in the application database. All secrets are held in a dedicated secrets manager.
Data minimisation
The platform transmits only what is needed to sync tickets - using record IDs and metadata rather than raw ticket content.
Encrypted in transit and at rest
All data is encrypted via TLS in transit and encrypted at rest in storage. Data types are segregated across systems.
Continuous monitoring
Unusual activity is monitored continuously with detailed event logging across the platform.
Certifications
Independent verification that our security controls are real, not just documented.
ISO/IEC 27001
Information Security Management
Support Fusion is certified to ISO/IEC 27001, the international standard for information security management. The certification covers our risk management processes, security controls, and ongoing operational practices — independently audited and verified by an accredited body.
For enterprise procurement teams, we can provide our certificate and Statement of Applicability on request.
SOC 2 Type II
Service Organisation Controls
SOC 2 Type II certification is currently underway. The audit evaluates our security, availability, and confidentiality controls over a defined operating period. Completion is expected before the end of 2026.
If you have a procurement requirement that needs our current security posture in writing, get in touch and we can provide documentation.
Visit the Support Fusion Trust Center
Register for self-serve access to policy details, certifications, and compliance documentation. Need something specific? Submit a vendor security questionnaire directly through the portal.
Security questions
Do we need to create user accounts for our IT service providers in our ITSM?
Does Support Fusion store our ticket data?
What authentication method does Support Fusion use to connect to my ITSM?
What permissions does Support Fusion need on our ITSM?
How does Support Fusion handle data security?
Is Support Fusion SOC 2 certified?
Does Support Fusion support single sign-on?
How does Support Fusion handle API credentials and secrets?
What ticket data does Support Fusion actually transmit?
How is payment data protected?
How does Support Fusion test for security vulnerabilities?
Who controls API keys and permissions in Support Fusion?
Where do I submit a vendor security questionnaire?
Have a specific security question?
An integration specialist will run the session, tailored to your platforms. We'll walk through how sync would work for your team and answer any questions along the way.
Get in touch