Skip to content

Security & Trust

Last updated: August 2026

How we protect customer data — and model the standards we help our customers meet.

1. Our approach

We sell compliance, so we hold this site and our product to the standards we help customers meet. Security is built on best practices — role-based access, audit trails, document sign-off and encryption — and on clear controls that make sensitive actions reviewable.

2. Application security (this site)

  • HTTPS everywhere, with HSTS and automatic HTTP→HTTPS upgrade.
  • A strict, nonce-based Content Security Policy on every response.
  • Hardened headers: X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy.
  • Site analytics include Vercel Web Analytics, Speed Insights and Google Analytics 4. GA4 runs in Advanced Consent Mode: before you consent, analytics storage remains denied, but Google may receive cookieless measurements. Analytics cookies and full measurement are enabled only after you opt in. We use no advertising pixels or client-side secrets.
  • Contact-form input is validated server-side with spam and rate-limit protection.

3. Data protection & encryption

Data is encrypted in transit using TLS. For the product, data is encrypted at rest and access is scoped to least privilege.

4. Access controls

Role-based access control, audit logging and documented approval workflows protect sensitive data and provide an evidenced trail.

5. Infrastructure & hosting

This marketing site is deployed on Vercel, whose hosting infrastructure uses Amazon Web Services (AWS). Customer environments use managed cloud infrastructure with encryption in transit and at rest and least-privilege access. Private cloud hosting and data-residency options are available for enterprise customers.

6. Data ownership & portability

Your compliance program remains portable. You can export your data at any time and keep a complete record of the controls, evidence and approvals your team manages.

7. Compliance status

SOC2Start is committed to strong security practices and is working toward its own formal certifications. We do not currently claim to hold a SOC 2 (or other) certification. This page will be updated with any certification status once independently verified.

8. Responsible disclosure

Found a vulnerability? We appreciate responsible disclosure. Please email compliance [at] soc2start [dot] io with details and steps to reproduce.

9. Contact

Security questions or documentation requests? Email compliance [at] soc2start [dot] io or visit our trust center.

Get audit-ready. Stay in control.

Start with one framework and one user free. Every signup includes 30 days of Pro features.

Security & Trust · SOC2Start.io