SECURITY
SOC 2 roadmap.
Straight answer: we do not yet hold a SOC 2 report (an independent audit of a company's security controls), and we won't claim controls we haven't implemented. Here's exactly where we are and the path we're on.
Plenty of early companies put a "SOC 2" badge in their footer before they've been audited. We won't. A SOC 2 Type II report is earned by an independent auditor testing your controls over a real observation window — until that report exists, we'll tell you precisely what is and isn't true. The controls below marked In place today are operating now; the rest are honestly labeled in progress or planned.
Data handling
Zero-retention API terms with our LLM vendors (the AI model providers we rely on); we never train models on customer content. Customer data is encrypted in transit and at rest.
Sub-processors
Named sub-processor list with 30-day notice before adding new ones. One set of data-protection terms covers the platform.
Access control
Role-based access on the portal; least-privilege internal access to production (staff reach only what their job requires); audit logging on customer (tenant) workspaces.
Data lifecycle
Customer-initiated export at any time; deletion of customer content within 30 days of account closure.
Formal policies
Writing the policy set a SOC 2 audit expects — information security, incident response, change management, vendor management, access review.
Monitoring & logging
Centralizing infrastructure logging and alerting — the evidence an auditor needs that monitoring runs continuously.
Readiness assessment
Engage an independent firm for a gap assessment against the SOC 2 Trust Services Criteria — the checklist of controls the audit measures against.
Type II observation
Run the observation window during which an auditor tests controls over time, then issue the Type II report.
The path
We're not publishing a target date we can't guarantee. If you need a specific timeline, our current control matrix, or a security questionnaire completed, we'll share specifics under NDA.
What you can rely on today
Ahead of a SOC 2 report, these are contractual and operational commitments we'll stand behind in writing:
Security review or data questions?
We respond within one business day and will complete standard security questionnaires. For control details or our roadmap timeline, ask under NDA.