← Back to Home

Trust & Security

Last Updated: August 13, 2026

POG ERP is built and operated by a small US-based team. We take security seriously because your business depends on it. This page summarizes how we protect your data, who we share it with, and how to reach us with questions.

Compliance status: POG ERP is not currently SOC 2 certified. We maintain an internal SOC 2 readiness program and are working toward an independent assessment when the business stage justifies it.

Where your data lives

Customer data is hosted in Oracle Cloud Infrastructure, US-East region (Ashburn, Virginia). Data does not leave the United States in normal operation. Static assets and DNS are served through Cloudflare's global edge network.

Encryption

Authentication & access

Sub-processors

POG ERP uses the following sub-processors to provide the Service. This table is the public sub-processor disclosure for active services. We notify customers of material changes to this list.

Sub-ProcessorPurposeData CategoriesLocation
Oracle CloudInfrastructure hosting, database, storageApplication data, backups, infrastructure metadataUnited States
CloudflareCDN, DNS, edge securityTraffic metadata, DNS records, static asset requestsGlobal
StripePayment processing and billingBilling records, payment metadata, Stripe account referencesUnited States
TelnyxVoice and SMS infrastructurePhone numbers, SMS content, voice/call metadataUnited States
SentryError monitoring and alertingStack traces, error metadata, scrubbed request contextUnited States
GitHubSource control and deploy pipelineSource code, deployment configuration, workflow logsUnited States
Google (Gemini)AI follow-up generationLead/customer context needed for AI draft generationUnited States
GroqAI inference fallbackLead/customer context needed for AI draft generation, if activeUnited States
DeepgramVoicemail transcriptionVoicemail audio and transcripts, if activeUnited States
WisetackCustomer financing offersFinancing application data processed directly by Wisetack, if activeUnited States
OpenStreetMap (Nominatim)Address geocodingAddress strings onlyGlobal

Tenant data isolation

Backups & disaster recovery

Monitoring & reliability

Outbound messaging safety

Compliance

Application security

Security policies

We maintain formal internal security policies covering access control, incident response, change management, vendor management, data retention, backup and disaster recovery, and security awareness. These policies are reviewed on a quarterly, semi-annual, or annual cadence and align with industry-standard control frameworks. POG ERP is not SOC 2 certified.

Incident response

We follow a documented incident playbook. Confirmed security incidents affecting customer data are reported to affected customers without undue delay and within 72 hours of confirmation, subject to investigation, law enforcement, and legal requirements.

Reporting a vulnerability

If you believe you've found a security issue, please email management@potomacops.com with details. We'll acknowledge receipt within 2 business days. Please do not publicly disclose until we've had a chance to investigate and remediate. A machine-readable disclosure file is available at /.well-known/security.txt.

Contact
Potomac Operations Group LLC
Email: management@potomacops.com
Website: www.potomacops.com