Skip to content
DENDRITES AI

SECURITY

SOC 2 roadmap.

Straight answer: we do not hold a SOC 2 report yet, and we won't claim controls we haven't implemented. Here's exactly where we are and the path we're on.

Plenty of early companies put a "SOC 2" badge in their footer before they've been audited. We won't. A SOC 2 Type II report is earned by an independent auditor testing your controls over a real observation window — until that report exists, we'll tell you precisely what is and isn't true. The controls below marked In place today are operating now; the rest are honestly labeled in progress or planned.

In place todayIn progressPlanned
In place today

Data handling

Zero-retention API terms with our LLM vendors; we never train models on customer content. Customer data is encrypted in transit and at rest.

In place today

Sub-processors

Named sub-processor list with 30-day notice before adding new ones. One DPA covers the platform.

In place today

Access control

Role-based access on the portal; least-privilege internal access to production; audit logging on tenant workspaces.

In place today

Data lifecycle

Customer-initiated export at any time; deletion of customer content within 30 days of account closure.

In progress

Formal policies

Writing the policy set a SOC 2 audit expects — information security, incident response, change management, vendor management, access review.

In progress

Monitoring & logging

Centralizing infrastructure logging and alerting to evidence continuous monitoring controls.

Planned

Readiness assessment

Engage an independent firm for a gap assessment against the SOC 2 Trust Services Criteria.

Planned

Type II observation

Run the observation window during which an auditor tests controls over time, then issue the Type II report.

The path

01 ✓
Controls in place
The data-handling, access, and lifecycle controls above — already operating.
02
Policy + evidence
Formalize policies and centralize the evidence an audit requires.
03
Readiness assessment
Independent gap assessment against the Trust Services Criteria.
04
Type II observation
Auditor tests controls across an observation window.
05
Report issued
SOC 2 Type II report available to customers under NDA.

We're not publishing a target date we can't guarantee. If you need a specific timeline, our current control matrix, or a security questionnaire completed, we'll share specifics under NDA.

What you can rely on today

Ahead of a SOC 2 report, these are contractual and operational commitments we'll stand behind in writing:

Signable GDPR-aligned DPA
Named sub-processors · 30-day change notice
Zero-retention LLM API terms
No training on customer content
Full data export on request
Deletion within 30 days of closure

Security review or DPA?

We respond within one business day and will complete standard security questionnaires. For control details or our roadmap timeline, ask under NDA.