Skip to Main Content
Information Security at SOCi — Light
Security & Trust

Security is built into every layer of the SOCi platform.

SOCi protects customer, employee, and AI data through a security program aligned to the AICPA Trust Services Criteria — combining independently audited controls, layered technical safeguards, and continuous monitoring across our infrastructure.

SOC 2 Type II SOC 3 ISO/IEC 27001 ISO/IEC 27701 ISO/IEC 42001 HIPAA-aligned
01 — Commitment

A program built on the AICPA Trust Services Criteria

Our information security program integrates policy, process, and technology across security, availability, processing integrity, confidentiality, and privacy — the five principles that make up the AICPA Trust Services Criteria. Rather than treating security as a single team's responsibility, SOCi distributes ownership across dedicated security leadership, engineering, and an executive-level oversight committee, with every control independently tested through our annual audit cycle.

02 — Governance

Security ownership, from the board room to the codebase

Chief Technology Officer
Holds executive accountability for the technology organization and its security posture, setting direction for the program at the leadership level.
Chief Information Security Officer (CISO) & VP
Leads the security and compliance function both strategically and operationally, owns the control framework, and serves as the primary point of contact for customer security reviews.
Principal Security Engineer
Designs and hardens security architecture across cloud infrastructure, applications, and the AI systems underpinning the SOCi platform.
Security DevOps Specialist
Embeds security tooling and guardrails directly into build and deployment pipelines so controls are enforced automatically, not bolted on after the fact.
Security & Compliance Analyst
Runs day-to-day monitoring, evidence collection, and audit coordination that keep certifications current year over year.
Information Security & Privacy Management Committee
A cross-functional group that reviews risk, approves policy changes, and provides executive oversight of the security and privacy program.
Mandatory security awareness educationRequired on onboarding and on a recurring basis for every employee and contractor, covering phishing, data handling, and incident reporting.
Advanced secure coding trainingEngineering teams receive targeted training on secure development practices to reduce vulnerabilities before code reaches production.
Formal change managementChanges to production systems follow documented review and approval steps, consistent with industry best practice.
03 — Technical Controls

Layered defenses across infrastructure

SOCi runs on Amazon Web Services and Google Cloud Platform, with controls layered at the network, host, and application level.

Cloud infrastructure

Hosted on AWS and Google Cloud Platform, giving SOCi the physical security, redundancy, and compliance inheritance of enterprise-grade cloud providers.

Continuous monitoring & SIEM

Security information and event management tooling correlates signals across the environment for continuous, around-the-clock visibility.

Independent vulnerability assessment

Regular penetration testing and vulnerability assessments performed by CREST-certified firms, with findings tracked to remediation.

Endpoint protection

Antivirus and malware prevention deployed across company endpoints, backed by centralized detection and response.

Backup & disaster recovery

Critical systems are backed up on a regular schedule under a documented disaster-recovery strategy designed to limit data loss and downtime.

Network defense

Next-generation firewalls paired with intrusion detection and prevention systems monitor and filter traffic at the network boundary.

Identity & access management

Strong authentication and least-privilege access controls govern who can reach systems and data, and what they can do once inside.

Change management

Production changes move through documented review, testing, and approval gates before release.

Bug bounty program

An active, ongoing bug bounty program invites independent researchers to help identify and responsibly report vulnerabilities.

04 — Data Protection

Encryption at rest and in transit

Data is encrypted throughout its lifecycle using industry-standard algorithms such as TLS 1.2+, HTTPS, and AES 256 — on disk, in the database, and while moving across the network.

LayerProtection
StorageWhole-disk encryption + partition/file-level encryption
DatabaseDatabase-level encryption at rest
TransmissionHTTPS / SSH using AES, 3DES, and TLS 1.2+
05 — Compliance & Certifications

Independently audited, continuously maintained

SOCi's controls are validated on a recurring basis by independent third-party auditors.

SOC 2 Type II

Independently audited controls for security, availability, and confidentiality over an extended review period, per AICPA standards.

SOC 3

A general-use report summarizing our SOC 2 results, available to share publicly without an NDA. Download the SOC 3 report ↗

ISO/IEC 27001

Certification of SOCi's information security management system (ISMS), covering risk management and control implementation.

ISO/IEC 27701

Extends the ISMS to privacy information management, aligning our practices with global data protection expectations including GDPR.

ISO/IEC 42001 2023

Certification of our AI management system — formal governance over how AI capabilities are developed, deployed, and monitored across the platform.

HIPAA-aligned controls

Controls mapped to HIPAA safeguards, with a Business Associate Agreement available on request for customers handling protected health information.

06 — Trust Center

Self-serve access to our audit evidence

SOCi's Trust Center, powered by SafeBase, lets customers and prospects review our security posture directly and download audit documentation for their own reviews.

  • SOC 2 report & SOC 3 report
  • ISO 27001, 27701 & 42001 certificates
  • HIPAA report
  • Data flow & network diagrams
  • Cyber insurance documentation
  • Customer audit rights

Reviewed sub-processors

Third parties that may process customer data as part of the SOCi platform, disclosed in full on the Trust Center:

Amazon Web Services Google Cloud Microsoft Salesforce OpenAI

Found a vulnerability?

SOCi maintains an active bug bounty and coordinated disclosure program. If you believe you've found a security issue affecting SOCi, we want to hear from you — report it to [email protected].

Isn’t it time you had a Marketing Platform that does the work for you?

Get started
Asterisks (*) indicate required fields.