Compliance
SOC 2
Type I audit in progress.
Security controls
Select a category to see its controls.
Access control
- Multi-factor authentication
- Role-based access control
- Access provisioning
- Access termination
- Periodic access reviews
Business continuity
- Backups
- Backup testing
- Contingency plan
- Capacity planning
Change management
- Code review
- Software development life cycle
- Configuration management
- Authorized software list
Incident response
- Incident response plan
- Incident reporting
- Incident response testing
Information security
- Information security policy
- Security leadership role
- Periodic self-assessments
Personnel security
- Background checks
- Security awareness training
- Access agreements and NDAs
System protection
- Encryption at rest and in transit
- Logging and monitoring
- Vulnerability management
- Network segmentation
- Penetration testing
Third-party risk
- Vendor reviews
- Third-party agreements
- Third-party risk management policy
Sub-processors
Third parties that may process customer data.
AWS
Cloud infrastructure hosting
USA
Google Cloud Platform
Cloud infrastructure hosting
USA
Microsoft Azure
Cloud infrastructure hosting
USA
Anthropic
LLM provider for AI-assisted workflows
USA
OpenAI
LLM provider for AI-assisted workflows
USA
Google Workspace
Business productivity (email, docs, calendar)
USA
Documents
SOC 2 status
Where the Type I audit stands and which controls it covers
Security overview
Architecture, security boundaries, and controls
Privacy Policy
How we handle personal data
Terms of Service
Terms governing use of the website
Sub-processor list
Third parties that process customer data