Security & Trust
Last updated: August 2026
How we protect customer data — and model the standards we help our customers meet.
1. Our approach
We sell compliance, so we hold this site and our product to the standards we help customers meet. Security is built on best practices — role-based access, audit trails, document sign-off and encryption — and on clear controls that make sensitive actions reviewable.
2. Application security (this site)
- HTTPS everywhere, with HSTS and automatic HTTP→HTTPS upgrade.
- A strict, nonce-based Content Security Policy on every response.
- Hardened headers: X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy.
- Site analytics include Vercel Web Analytics, Speed Insights and Google Analytics 4. GA4 runs in Advanced Consent Mode: before you consent, analytics storage remains denied, but Google may receive cookieless measurements. Analytics cookies and full measurement are enabled only after you opt in. We use no advertising pixels or client-side secrets.
- Contact-form input is validated server-side with spam and rate-limit protection.
3. Data protection & encryption
Data is encrypted in transit using TLS. For the product, data is encrypted at rest and access is scoped to least privilege.
4. Access controls
Role-based access control, audit logging and documented approval workflows protect sensitive data and provide an evidenced trail.
5. Infrastructure & hosting
This marketing site is deployed on Vercel, whose hosting infrastructure uses Amazon Web Services (AWS). Customer environments use managed cloud infrastructure with encryption in transit and at rest and least-privilege access. Private cloud hosting and data-residency options are available for enterprise customers.
6. Data ownership & portability
Your compliance program remains portable. You can export your data at any time and keep a complete record of the controls, evidence and approvals your team manages.
7. Compliance status
SOC2Start is committed to strong security practices and is working toward its own formal certifications. We do not currently claim to hold a SOC 2 (or other) certification. This page will be updated with any certification status once independently verified.
8. Responsible disclosure
Found a vulnerability? We appreciate responsible disclosure. Please email compliance [at] soc2start [dot] io with details and steps to reproduce.
9. Contact
Security questions or documentation requests? Email compliance [at] soc2start [dot] io or visit our trust center.
Get audit-ready. Stay in control.
Start with one framework and one user free. Every signup includes 30 days of Pro features.