Security at ReadySOC

Your compliance data is sensitive. Here's exactly how we protect it โ€” no marketing fluff.

Built with security in mind

ReadySOC helps startups prepare for SOC 2 audits. We hold ourselves to the same security standards we help our customers achieve.

๐Ÿ”’

Data isolation

Every company workspace is completely isolated. No company can ever access another company's controls, evidence, or team data.

๐Ÿ›ก

Secure file storage

Every file you upload is stored in a private, non-public location on our servers โ€” it cannot be accessed by guessing or constructing a URL. Every download is verified against your account and company before anything is served.

๐Ÿ”‘

No passwords

We use magic link authentication. No passwords means no password reuse, no credential stuffing, and no password database to breach.

What we do to protect you

Specific, concrete measures โ€” not vague promises.

โœ“
TLS encryption in transit All traffic between your browser and ReadySOC is encrypted via HTTPS/TLS. HTTP connections are redirected to HTTPS automatically.
โœ“
Magic link authentication Sign-in links expire after 15 minutes and can only be used once. Sessions are protected by secure browser cookies with a 30-day expiry.
โœ“
Evidence file security Uploaded files are stored in a private location with randomized names. Every download requires you to be signed in and verified as a member of the correct company workspace.
โœ“
Per-company data isolation Every database query is scoped to your company ID. There is no path โ€” at the application or database level โ€” for one company to read another company's data.
โœ“
Security monitoring We log access activity for security monitoring purposes. IP addresses are anonymized before storage โ€” we never retain full identifying network information.
โœ“
Rate limiting Login requests and form submissions are rate-limited to prevent brute force and abuse.
โœ“
Protection against common attacks All data submitted to ReadySOC is validated and sanitized to protect against common web attacks including injection attacks and unauthorized access attempts.
โœ“
File upload controls Evidence uploads are restricted to known safe document types (PDF, Word, Excel, images, CSV). File size is capped at 10MB per file to prevent abuse.
โœ“
Browser security controls We configure industry-standard browser security controls on all pages to prevent clickjacking, content spoofing, and other browser-based attacks.
โœ“
No third-party tracking We don't use advertising trackers, behavioral analytics, or third-party pixels. No Google Analytics, no Meta Pixel, no ad networks.
โœ“
AI data boundaries AI guidance features send only control IDs and status to our AI provider โ€” never your uploaded evidence files, company name, or personal information.

Where your data lives

We believe you should know exactly where your data lives and who touches it.

Data location
United States
All data is stored on servers located in the US. No international data transfers.
Data storage
Encrypted at rest
Your compliance data and uploaded files are stored securely with regular automated backups.
File security
Private and isolated
Uploaded evidence files are stored privately, isolated per company, and never publicly accessible.
AI provider
Anthropic
Powers compliance guidance only. Your uploaded documents and personal data are never shared with Anthropic.
Payment processing
Stripe
We never store or see your payment card details. Stripe is independently PCI-DSS certified.
Email delivery
Dedicated mail server
Sign-in links and notifications are sent from our own dedicated mail server โ€” not a shared bulk email provider.

๐Ÿ” Vulnerability disclosure

If you discover a security vulnerability in ReadySOC, please report it responsibly before public disclosure. We take all reports seriously and will respond within 48 hours.

Email: security@readysoc.com โ€” please include a description of the issue, steps to reproduce, and your contact information. We do not currently offer a bug bounty program but we will acknowledge your contribution.

Preparing your own SOC 2 report?

ReadySOC helps startups track all 21 Trust Service Criteria controls, collect evidence, and generate audit-ready reports โ€” so you can show your customers the same transparency we show you.

Join the waitlist โ†’

Questions about security? Email security@readysoc.com
Last updated: July 11, 2026 ยท STAR LL, Nevada LLC