Trust · Compliance
Trust & compliance posture
socbox.cloud is built by security operators. Everything below is what we’d want a vendor we’re evaluating to tell us — clearly, in one place, without a “contact sales” gate.
Security commitments
- Strong encryption in transit and at rest.
- Authenticated, mutually-encrypted communication between internal services; default-deny network isolation.
- Signed, verified build artifacts.
- Audit logging on paid plans is planned; retention terms will be published when it ships.
- Vulnerability disclosure: email security@socbox.cloud with a public PGP key. Bug bounty coming at GA.
Incident response
Any security incident affecting your data triggers a written notification to your account email, and a post-mortem once the incident is closed. We are deliberately not publishing response-time commitments until we can staff them; when we can, they will appear here first.
Asks before signing
Need a counter-signed DPA, a custom SCC, or a vendor-security questionnaire? Email support@socbox.cloudwith your timeline and we’ll turn it around as quickly as we can.