Trust Center

Innovation starts with trust.

At Above Promotions, we believe that true impact is built on a foundation of integrity, security, and ethical partnership. It’s not simply what we deliver in marketing and technology, but how we deliver it.

We are driven to be a force for good for our clients and their communities. We design our Innovation Lab technologies, from AI to MarTech, intentionally and responsibly, so they amplify your brand’s positive message.

Grounded by our comprehensive Code of Ethics and a commitment to the NIST Cybersecurity Framework, we innovate to achieve results while rigorously protecting client confidentiality and privacy. We work to be transparent, predictable, and accountable, solidifying the trust that lets us operate at the intersection of innovation and impact.

Scope of Applicability. This Trust Center describes Above Promotions LLC’s general security, privacy, and ethical posture. Specific contractual obligations, service levels, performance commitments, or data-handling practices may vary based on the nature of the engagement, membership tier, or applicable written agreement. It is provided for transparency and informational purposes only and does not create contractual obligations unless expressly incorporated into a written agreement.

Our foundation of trust: security, ethics, and enterprise readiness.

We build and implement advanced marketing technology and deliver communications training that organizations rely on. This Trust Center explains how we protect data, operate responsibly (including AI), and meet the rigorous security and compliance expectations of enterprise, government, and public-sector buyers.

Above Promotions, where innovation meets impact. This is evidence of our impact.

Last reviewed and updated: January 26, 2026

Section 01

Security: enterprise-grade protection

Our security posture is not just a checklist; it’s a strategic commitment built on the NIST Cybersecurity Framework (CSF). This standard ensures we proactively manage risk across all our divisions.

Owner: Technology Manager  ·  Contact: [email protected]

FeatureTechnical DetailPlain-English Summary
FrameworkNIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover). Regularly audited.We constantly scan for weaknesses. In a critical incident we have a clear, tested plan to contain it, and we notify impacted clients within 72 hours of discovery.
Vulnerability & IRVulnerability Management: critical findings remediated within 7 days (SLA). Incident Response Plan: established roles and communication protocols.We are prepared for the unexpected. We can restore our core services within hours, ensuring minimal data loss and project continuity.
Business ContinuityNightly encrypted backups, cross-region replication. Recovery Time Objective (RTO): 4 hours. Recovery Point Objective (RPO): 2 hours.We are prepared for the unexpected. We can restore core services within hours and ensure minimal data loss, guaranteeing project continuity.
Availability TargetExpected platform uptime (excluding scheduled maintenance) is 99%.Our commitment to reliability means you can count on us to be available when you need us.

Security Contact & Vulnerability Disclosure: We welcome security-researcher collaboration and promote safe disclosure. We publish a security.txt file at https://www.abovepromotions.com/.well-known/security.txt with our current contact details and policy link for responsible vulnerability reporting.

Section 02

Responsible AI: ethical innovation

Responsible AI Scope. This section describes internal principles and governance practices related to artificial intelligence. It does not create guarantees or contractual obligations.

Our Innovation Lab uses Machine Learning and Artificial Intelligence to deliver cutting-edge solutions, always governed by our Code of Ethics and a commitment to transparency.

Strategic focus: trustworthy AI that drives ethical results, not risk.

PrincipleOur CommitmentPlain-English Summary
Confidentiality & PrivacyNo customer content is used for general model training by default. Any client-specific fine-tuning requires explicit consent via the SOW.Your proprietary data is yours. We don’t use it to train the AI we use for other clients.
Transparency & AccountabilityOutputs generated or heavily influenced by AI are marked with disclosure badges. All content is subject to a mandatory human-override and review process.You’ll always know when AI has been used, and a skilled AP professional is always responsible for the final quality and accuracy.
Fairness & Non-DiscriminationWe adhere to our Human Rights Policy to actively mitigate bias in content generation, ensuring outputs are respectful and equitable.We actively work to ensure our AI tools do not perpetuate bias or create discriminatory content.

AI-assisted tools may process client-provided materials solely to deliver requested services. Client content is not incorporated into shared or external model training without explicit written consent. Final responsibility for review, approval, and use of AI-assisted outputs remains with the client.

Section 03

Compliance & certifications

Our ethical framework is the foundation of our entire operation, ensuring we meet regulatory, ethical, and contractual obligations.

  • Ethical Core (Code of Ethics): Our firm operates on the principles of Integrity, Confidentiality, and Compliance. Client materials and credentials are handled under strict Confidentiality rules, enforced during the AP Internal New Client Onboarding Process.
  • Human Rights: We are committed to our Human Rights Policy, ensuring fair labor practices and non-discrimination across our operations.
  • Regulatory Alignment: Our NIST-based security program is designed to align with security best practices for GDPR and PCI DSS.

Data Processing Addendum (DPA) & Subprocessors

We rely on carefully vetted third parties (Subprocessors) to provide specialized services.

  • Contracting: Standard Master Service Agreements (MSA) and a comprehensive Data Processing Addendum (DPA) are provided to all clients.
  • Breach Notification: We contractually guarantee notification of any material data breach to the affected client within 72 hours.
  • Subprocessor List: The complete list of third-party subprocessors who handle or store client data is considered proprietary and is available for review under NDA in our Document Room.

Section 04

Reliability, business continuity & status

We view reliability as a critical component of client service, ensuring high availability for all platforms used in campaign execution and client collaboration.

  • Accessibility: We are committed to inclusive design, striving for WCAG 2.1 AA compliance across all client-facing digital products and training materials. Accessibility concerns should be reported through designated contact channels for prompt investigation and remediation.
  • Live Status: You can check the live status and operational updates of our primary services, including the Innovation Lab and Client Portal.

Availability targets reflect internal performance objectives and do not constitute service-level guarantees unless expressly stated in a written agreement.

Section 05

Document Room (for due diligence)

For enterprise, federal, and defense clients requiring formal due diligence, the following documents are available under a Non-Disclosure Agreement (NDA):

  • Subprocessor List & Changelog
  • SOC 2 Type II Report (when available)
  • External Penetration Test Executive Summary
  • Detailed Control Mappings (NIST CSF, ISO 27001)
  • Business Continuity Plan & Incident Response Policy Summaries

Ready to engage?

Our commitment to the NIST framework and ethical AI is your assurance of a secure partnership. Contact our sales or procurement team to request access to the Document Room.

Request Document Room Access →