SOC 2 Type II
Scope: Security, Availability, Confidentiality. Covers the Soldius production platform, supporting infrastructure, and the personnel operating it.
Request the report under NDA →Soldius is independently audited to SOC 2 Type II and ISO 27001, with HIPAA-ready infrastructure deployed across 38 countries and a 99.98% uptime SLA. This page is the dossier your security team would otherwise request during procurement — laid out so it can be reviewed, exported, and signed off without a back-and-forth.
The alphabet soup — SOC 2, ISO 27001, HIPAA — collapses into a single promise: your call audio, transcripts, and CRM-mirrored data are handled by infrastructure that has been independently audited against the controls a CISO already trusts. Soldius holds SOC 2 Type II (not Type III) and ISO 27001:2022; HIPAA-ready infrastructure is available under a signed Business Associate Agreement; GDPR and CCPA alignment is documented in our Data Processing Addendum. Audit reports, penetration-test summaries, and the latest SOC 2 bridge letter are exportable on request under NDA.
Reports are refreshed annually and updated through a continuous-monitoring program. The most recent SOC 2 observation window closed March 2025.
A scannable register of every audited framework Soldius maintains, the scope of coverage, the auditor, and the date the most recent report was issued. Copy any row straight into your vendor questionnaire.
Scope: Security, Availability, Confidentiality. Covers the Soldius production platform, supporting infrastructure, and the personnel operating it.
Request the report under NDA →Scope: Information Security Management System (ISMS) covering product engineering, ML pipeline, customer data handling, and corporate IT.
Request the certificate →Scope: Encrypted storage of protected health information (PHI), BAA-eligible tenants, audited access controls, and signed Business Associate Agreements.
Request a BAA →Scope: Lawful basis, data-subject rights, sub-processor disclosure, breach notification within 72 hours, and Standard Contractual Clauses for cross-border transfers.
Request the DPA →Measured monthly against the trailing 12-month window. Historical performance and live incident history are publicly visible at status.soldius.com. Service credits are issued automatically for any month falling below the committed SLA.
Primary processing region for North-American customers. Backed by AWS US-East-1 with cross-region failover to US-West-2.
Frankfurt and Dublin regions. SCCs and UK addendum pre-signed; no data leaves the EU boundary for processing.
Singapore and Tokyo regions. Local processing for APAC customers under local data-protection regimes.
Call audio, transcripts, and CRM-mirrored records are processed and stored in the region selected at tenant creation. Soldius currently operates across 38 countries with regional processing available in the United States, the European Union, and Asia-Pacific.
All customer data — audio, transcripts, embeddings, CRM mirrors — encrypted with AES-256 using envelope encryption and customer-scoped KMS keys.
All client-to-server and inter-service traffic uses TLS 1.3 with modern cipher suites. HSTS preload enabled on every Soldius domain.
Bring-your-own-key or hold-your-own-key options available for Enterprise tier through AWS KMS and HashiCorp Vault integrations.
Default 24 months, configurable down to 30 days. Customer-initiated purge within 30 days of contract termination.
A condensed map of the access, identity, and operational controls Soldius maintains — each paired with the artifact a security architect can request during review.
SAML 2.0 single sign-on with Okta, Azure AD, Google Workspace, Ping, JumpCloud, and any IdP that exposes a SAML metadata URL. SCIM 2.0 provisioning syncs users and groups in real time; de-provisioning is enforced within 60 seconds of an HR-system event.
Five default roles (Owner, Admin, Manager, Rep, Viewer) with field-level permissions on transcript visibility, PII redaction overrides, and CRM-write scopes. Custom roles available on Enterprise tier.
Every read, write, export, and admin action is captured in an immutable audit log retained for 13 months. Streams to Splunk, Datadog, Panther, or any S3-compatible bucket via Kinesis Firehose.
Annual third-party penetration test by a CREST-accredited firm, plus quarterly internal red-team exercises. Critical findings resolved within 7 days; high-severity within 30 days. Bug-bounty program live on HackerOne.
Background checks on every employee and contractor. Mandatory security and privacy training on hire and quarterly thereafter. Annual SOC 2 + ISO 27001 refresher attestations.
24/7 incident response on-call rotation. Customer notification within 72 hours of a confirmed breach — sooner when required by GDPR, CCPA, or contractual commitments. Post-mortems published for material incidents.