Security is built into every layer of the SOCi platform.
SOCi protects customer, employee, and AI data through a security program aligned to the AICPA Trust Services Criteria — combining independently audited controls, layered technical safeguards, and continuous monitoring across our infrastructure.
A program built on the AICPA Trust Services Criteria
Our information security program integrates policy, process, and technology across security, availability, processing integrity, confidentiality, and privacy — the five principles that make up the AICPA Trust Services Criteria. Rather than treating security as a single team's responsibility, SOCi distributes ownership across dedicated security leadership, engineering, and an executive-level oversight committee, with every control independently tested through our annual audit cycle.
Security ownership, from the board room to the codebase
Layered defenses across infrastructure
SOCi runs on Amazon Web Services and Google Cloud Platform, with controls layered at the network, host, and application level.
Cloud infrastructure
Hosted on AWS and Google Cloud Platform, giving SOCi the physical security, redundancy, and compliance inheritance of enterprise-grade cloud providers.
Continuous monitoring & SIEM
Security information and event management tooling correlates signals across the environment for continuous, around-the-clock visibility.
Independent vulnerability assessment
Regular penetration testing and vulnerability assessments performed by CREST-certified firms, with findings tracked to remediation.
Endpoint protection
Antivirus and malware prevention deployed across company endpoints, backed by centralized detection and response.
Backup & disaster recovery
Critical systems are backed up on a regular schedule under a documented disaster-recovery strategy designed to limit data loss and downtime.
Network defense
Next-generation firewalls paired with intrusion detection and prevention systems monitor and filter traffic at the network boundary.
Identity & access management
Strong authentication and least-privilege access controls govern who can reach systems and data, and what they can do once inside.
Change management
Production changes move through documented review, testing, and approval gates before release.
Bug bounty program
An active, ongoing bug bounty program invites independent researchers to help identify and responsibly report vulnerabilities.
Encryption at rest and in transit
Data is encrypted throughout its lifecycle using industry-standard algorithms such as TLS 1.2+, HTTPS, and AES 256 — on disk, in the database, and while moving across the network.
| Layer | Protection |
|---|---|
| Storage | Whole-disk encryption + partition/file-level encryption |
| Database | Database-level encryption at rest |
| Transmission | HTTPS / SSH using AES, 3DES, and TLS 1.2+ |
Independently audited, continuously maintained
SOCi's controls are validated on a recurring basis by independent third-party auditors.
SOC 2 Type II
Independently audited controls for security, availability, and confidentiality over an extended review period, per AICPA standards.
SOC 3
A general-use report summarizing our SOC 2 results, available to share publicly without an NDA. Download the SOC 3 report ↗
ISO/IEC 27001
Certification of SOCi's information security management system (ISMS), covering risk management and control implementation.
ISO/IEC 27701
Extends the ISMS to privacy information management, aligning our practices with global data protection expectations including GDPR.
ISO/IEC 42001 2023
Certification of our AI management system — formal governance over how AI capabilities are developed, deployed, and monitored across the platform.
HIPAA-aligned controls
Controls mapped to HIPAA safeguards, with a Business Associate Agreement available on request for customers handling protected health information.
Self-serve access to our audit evidence
SOCi's Trust Center, powered by SafeBase, lets customers and prospects review our security posture directly and download audit documentation for their own reviews.
- SOC 2 report & SOC 3 report
- ISO 27001, 27701 & 42001 certificates
- HIPAA report
- Data flow & network diagrams
- Cyber insurance documentation
- Customer audit rights
Reviewed sub-processors
Third parties that may process customer data as part of the SOCi platform, disclosed in full on the Trust Center:
Found a vulnerability?
SOCi maintains an active bug bounty and coordinated disclosure program. If you believe you've found a security issue affecting SOCi, we want to hear from you — report it to [email protected].
Security questions or a vendor review in progress?
[email protected] · Trust Center: trust.meetsoci.com
Christopher Dorr, CISO & VP of Information Security & Compliance