SECURITY
SOC 2 roadmap.
Straight answer: we do not hold a SOC 2 report yet, and we won't claim controls we haven't implemented. Here's exactly where we are and the path we're on.
Plenty of early companies put a "SOC 2" badge in their footer before they've been audited. We won't. A SOC 2 Type II report is earned by an independent auditor testing your controls over a real observation window — until that report exists, we'll tell you precisely what is and isn't true. The controls below marked In place today are operating now; the rest are honestly labeled in progress or planned.
Data handling
Zero-retention API terms with our LLM vendors; we never train models on customer content. Customer data is encrypted in transit and at rest.
Sub-processors
Named sub-processor list with 30-day notice before adding new ones. One DPA covers the platform.
Access control
Role-based access on the portal; least-privilege internal access to production; audit logging on tenant workspaces.
Data lifecycle
Customer-initiated export at any time; deletion of customer content within 30 days of account closure.
Formal policies
Writing the policy set a SOC 2 audit expects — information security, incident response, change management, vendor management, access review.
Monitoring & logging
Centralizing infrastructure logging and alerting to evidence continuous monitoring controls.
Readiness assessment
Engage an independent firm for a gap assessment against the SOC 2 Trust Services Criteria.
Type II observation
Run the observation window during which an auditor tests controls over time, then issue the Type II report.
The path
We're not publishing a target date we can't guarantee. If you need a specific timeline, our current control matrix, or a security questionnaire completed, we'll share specifics under NDA.
What you can rely on today
Ahead of a SOC 2 report, these are contractual and operational commitments we'll stand behind in writing:
Security review or DPA?
We respond within one business day and will complete standard security questionnaires. For control details or our roadmap timeline, ask under NDA.