Skip to content
DENDRITES AI

SECURITY

SOC 2 roadmap.

Straight answer: we do not yet hold a SOC 2 report (an independent audit of a company's security controls), and we won't claim controls we haven't implemented. Here's exactly where we are and the path we're on.

Plenty of early companies put a "SOC 2" badge in their footer before they've been audited. We won't. A SOC 2 Type II report is earned by an independent auditor testing your controls over a real observation window — until that report exists, we'll tell you precisely what is and isn't true. The controls below marked In place today are operating now; the rest are honestly labeled in progress or planned.

In place todayIn progressPlanned
In place today

Data handling

Zero-retention API terms with our LLM vendors (the AI model providers we rely on); we never train models on customer content. Customer data is encrypted in transit and at rest.

In place today

Sub-processors

Named sub-processor list with 30-day notice before adding new ones. One set of data-protection terms covers the platform.

In place today

Access control

Role-based access on the portal; least-privilege internal access to production (staff reach only what their job requires); audit logging on customer (tenant) workspaces.

In place today

Data lifecycle

Customer-initiated export at any time; deletion of customer content within 30 days of account closure.

In progress

Formal policies

Writing the policy set a SOC 2 audit expects — information security, incident response, change management, vendor management, access review.

In progress

Monitoring & logging

Centralizing infrastructure logging and alerting — the evidence an auditor needs that monitoring runs continuously.

Planned

Readiness assessment

Engage an independent firm for a gap assessment against the SOC 2 Trust Services Criteria — the checklist of controls the audit measures against.

Planned

Type II observation

Run the observation window during which an auditor tests controls over time, then issue the Type II report.

The path

01 ✓
Controls in place
The data-handling, access, and lifecycle controls above — already operating.
02
Policy + evidence
Formalize policies and centralize the evidence an audit requires.
03
Readiness assessment
Independent gap assessment against the Trust Services Criteria.
04
Type II observation
Auditor tests controls across an observation window.
05
Report issued
SOC 2 Type II report available to customers under NDA (non-disclosure agreement).

We're not publishing a target date we can't guarantee. If you need a specific timeline, our current control matrix, or a security questionnaire completed, we'll share specifics under NDA.

What you can rely on today

Ahead of a SOC 2 report, these are contractual and operational commitments we'll stand behind in writing:

Data-protection terms aligned with GDPR (the EU data-protection law)
Named sub-processors · 30-day change notice
Zero-retention LLM API terms
No training on customer content
Full data export on request
Deletion within 30 days of closure

Security review or data questions?

We respond within one business day and will complete standard security questionnaires. For control details or our roadmap timeline, ask under NDA.