Trust & Compliance - Everything procurement asks for, in one place.

Green Dolphin Software is structured for B2B enterprise engagement from day one. Insurance is in place. MSA and DPA templates are ready. Security posture is documented. Audit support is built into the standard contract.

Third-party verification - Independent reviews + verified provider credentials.

Green Dolphin Software is listed on the major B2B services platforms. Profiles are public, backlinks are active, and our Clutch profile is Verified — Clutch's third-party-vetted credential reserved for credentialed providers.

Recent engagements - A representative slice of the work.

Anonymized examples drawn from senior-architect-led engagements across regulated and mid-market industries. Each profile reflects the kind of fixed-bid SOW Green Dolphin returns within 3 business days of intake. Industry names + scope details are anonymized; specific case studies with named clients are added under NDA on request.

  • $75K·6 weeks

    Healthcare payer

    Bidirectional MuleSoft sync between Salesforce Health Cloud and Facets claims platform. Anypoint MQ for guaranteed delivery; Datadog observability; C4E governance handed off to internal team.

    Outcome: Replaced a $250K T&M quote from the incumbent SI with the same scope, on time, on budget.

  • $50K·5 weeks

    Mid-market manufacturer

    NetSuite ↔ Salesforce Sales Cloud customer + order sync. Workato recipes for HR-to-payroll. Canonical data model with masterless conflict resolution.

    Outcome: First production sync in week 3; full cutover with parallel-run validation by week 5.

  • $25K·3 weeks

    Fortune 100 retailer

    Architecture & Design only. Vendor-neutral iPaaS evaluation (MuleSoft vs Workato vs Boomi vs SnapLogic). Target-state topology, canonical model, 90-day modernization roadmap.

    Outcome: Fundable design package signed off by procurement the week after delivery.

  • $25K·4 weeks

    Mid-market financial services

    Salesforce Agentforce pilot with 4 custom actions over 2 data sources. Structured-output JSON schemas, prompt caching, confidence gating, full prompt + response logging to Splunk.

    Outcome: Procurement signed off without escalation — the audit trail was the differentiator.

  • $100K·12 weeks

    Public sector (state agency)

    Regulated MuleSoft platform setup with C4E governance, SAP RFC integration, multi-system canonical model. FedRAMP-aligned deployment topology with continuous monitoring.

    Outcome: Passed independent security review on first submission; no remediation cycle required.

  • $25K·2 weeks

    Aerospace & defense

    AI Document Processing engagement: intelligent extraction from supplier contracts into a structured Workato workflow. Claude with structured-output tool schemas, human-in-the-loop above threshold.

    Outcome: 12 hours of manual data entry per supplier collapsed to 8 minutes of review.

Insurance - Active coverage via Hiscox Insurance Company Inc (NAIC 10200).

Annually-renewed Professional Liability + Commercial General Liability + Cyber policy with Hiscox. Certificate of Insurance on the industry-standard ACORD 25 form, naming the client as Additional Insured where commercially available, issued within 24 hours of contract signature.

Professional Liability (Errors & Omissions)

Hiscox

$2M per claim / $2M aggregate

Claims-made policy covering claims arising from professional services — design errors, missed scope, integration defects discovered post-delivery.

Policy
P100.551.682.8
Period
09/18/2025 – 09/18/2026

Commercial General Liability

Hiscox

$2M per occurrence / $3M aggregate

Covers third-party bodily injury, property damage, and personal & advertising injury claims arising from business operations.

Policy
P100.551.342.8
Period
09/18/2025 – 09/18/2026

Cyber Liability / Network Security

Hiscox

$1M aggregate

Covers breach response, cyber extortion / ransomware, cyber crime (social engineering + funds transfer fraud), business interruption, data recovery, and privacy protection. Excludes criminal proceedings, infrastructure interruption, and intentional acts.

Policy
P106.590.226.1
Period
05/11/2026 – 05/11/2027

Legal & Contractual - MSA, DPA, and audit support.

Standard contracts ready to share with your legal team under NDA. We adapt to client paper where reasonable; our standard terms are designed to be acceptable to Fortune 500 procurement.

Master Services Agreement (MSA)

Standard fixed-bid MSA template available for download. California governing law. 50/50 payment terms (Net 15). Liability cap = fees paid in the 12 months preceding the claim, with carve-outs for confidentiality, indemnification, and gross negligence. Reviewed and approved for use.

Data Processing Addendum (DPA)

GDPR + CCPA + UK-GDPR compliant DPA available for download. Module 2 / Module 3 SCCs (EU 2021/914) for cross-border transfers. UK International Data Transfer Addendum for UK Personal Data. Sub-processor list maintained in DPA Annex 1. Reviewed and approved for use.

Certificate of Insurance (ACORD 25)

COI on ACORD 25 form (the industry-standard certificate format accepted by Fortune 500 procurement), naming the client as Additional Insured where commercially available. Issued by Hiscox within 24 hours of contract signature. Provided on request at any time during the engagement.

Compliance support

Engagements in regulated environments (HIPAA, SOX, FedRAMP, GDPR, CCPA, PCI-DSS, ISO 27001) supported. Compliance documentation pack included in Custom-tier engagements; available as add-on for Standard / Enterprise tiers.

HTML download opens in a new tab and is print-to-PDF ready. Markdown source is the authoritative version (used internally for redlines). Email max@greendolphin.ai for a Word or signed PDF version on company letterhead.

Security posture - Technical and organizational measures.

The complete list of measures from Annex 3 of our DPA. Reviewed and updated periodically.

Access control

SSO with multi-factor authentication on all admin systems (GitHub, Vercel, Google Workspace, Slack, Anthropic Console). FIDO2 hardware security keys for admin accounts. Quarterly access reviews. Encrypted laptops with full-disk encryption.

Secret management

API keys and credentials stored in encrypted secret managers (Google Secrets Manager, Vercel encrypted environment variables, GitHub Encrypted Secrets). Never committed to repositories. Rotation on personnel change.

Code review & deployment

No direct-to-prod commits. Source code reviewed before deployment. Static analysis + dependency scanning on every build. Open-source components license-vetted; CVE alerts monitored.

Source code custody

During an engagement, code lives in Green Dolphin's GitHub Organization. On delivery acceptance, repositories transfer to the client's GitHub Org (or a client-owned archive with full commit history) — full IP transfer.

Data in transit + at rest

TLS 1.2+ for all data in transit. Provider-managed encryption at rest (GitHub, Google Workspace, Slack). Production credentials separated from development; tested with non-production data wherever possible.

Personnel

Background checks on personnel handling client data. Confidentiality agreements signed before any client data access. Annual security awareness training.

Incident response

Documented incident response process. 48-hour client notification SLA on confirmed Personal Data Breach. Post-incident root-cause analysis shared with affected client within 30 days.

Audit support

Once per twelve-month period, clients (or third-party auditors bound by confidentiality) may audit Green Dolphin's compliance with the DPA. Standard SOC 2 / ISO 27001 attestations from sub-processors are passed through where applicable.

Sub-processors - Who else handles your data.

Per our DPA, the following sub-processors may handle Personal Data on a client's behalf in the course of providing Services. New sub-processors are notified to clients at least 30 days in advance per the DPA.

Sub-processorPurposeLocation
Vercel Inc.Website hosting (greendolphin.ai)USA
Resend (Easymail Inc.)Transactional email — intake form submissionsUSA / EU
Anthropic, PBCLLM API for the chatbot on greendolphin.aiUSA
Google LLC (Workspace)Email (max@greendolphin.ai), Calendar, DriveUSA / EU
Slack Technologies, LLCSlack Connect channels for client engagement communicationsUSA
GitHub, Inc.Source code repositories during engagementUSA

Need any of this for procurement?

Email max@greendolphin.ai with your request — Certificate of Insurance, MSA template, DPA template, security questionnaire response, or signed NDA. Standard turnaround within one business day.

Ready to scope an integration?

Six-step intake. Fixed-bid SOW returned in 3 business days. Basic integration from $10K; multi-integration engagements from $25K (3–5 integrations), then $50K/$75K/$100K+.

Office