SEOmise

Trust centre

The controls we run, stated plainly

How we protect the service and your data, organised by the SOC 2 Trust Services Criteria for security, availability and confidentiality.

Where we stand

We do not hold a SOC 2 report. SOC 2 is an attestation by an independent auditor (a licensed CPA firm) that controls are suitably designed (Type I) and, over a period of months, operated effectively (Type II). No software can be "SOC 2 compliant" by itself. What follows are the controls we operate and collect evidence for, so that an audit can take place; it is not a certification and should not be read as one.

Each control is marked in place when it is implemented and its automatic check, where there is one, is passing; otherwise it is marked in progress.

Security (common criteria)

ControlWhat it meansStatus
Security policies approved and reviewed
CC1.4, CC5.3
Written information security policies, approved by management, reviewed at least yearly and available to staff. In progress
Security awareness training
CC1.4, CC2.2
Everyone with access completes security awareness training when they join and every year. In progress
Risk assessment
CC3.1–CC3.4
A yearly risk assessment covering threats, fraud and changes to the service, with treatment decisions recorded. In progress
Two-step sign-in enforced for staff
CC6.1
Every staff account must use two-step sign-in (Security → Policies). In progress
Password policy
CC6.1
Long passwords, checked against known breaches, with lockout after repeated failures. In progress
Session timeout
CC6.1
Idle sessions end automatically (Security → Policies → idle timeout). In progress
Periodic access reviews
CC6.2, CC6.3
Staff access reviewed every quarter and workspace administrators every six months, with sign-off. In progress
Access removed when people leave
CC6.2
Leavers' staff accounts are disabled the same day; recorded in the audit log. In progress
Application firewall and blocking
CC6.6
Attack detection with automatic blocking is on and out of learning mode. In progress
Failed sign-ins monitored
CC7.2
Failed sign-ins are logged, accounts and addresses lock out, and staff are alerted to attacks. In progress
Tamper-evident audit log
CC7.2
Security-relevant actions are logged append-only with a hash chain that is verified and exported. In progress
Audit log retention
CC7.2
Audit entries are kept for at least a year (they are never pruned). In progress
Dependency updates and vulnerability scanning
CC7.1
Dependencies are updated at least quarterly and scanned (composer audit, npm audit). In progress
Incident response and breach register
CC7.3, CC7.4
An incident response plan, and a breach register that tracks the 72-hour notification deadline. In progress
Change management
CC8.1
Changes are reviewed and tested before release; production runs with debugging off. In progress
Vendor and sub-processor management
CC9.2
Sub-processors are listed publicly and reviewed every year. In progress

Availability

ControlWhat it meansStatus
Recent backups
A1.2
Daily database and file backups complete, with off-site copies. In progress
Backups verified and restore tested
A1.3
Backups are verified automatically; a restore is tested at least every quarter. In progress
Availability monitoring
A1.1
Components are checked continuously and incidents are published on the status page. In progress

Confidentiality

ControlWhat it meansStatus
Secrets encrypted at rest
CC6.1, C1.1
Platform settings and API keys are encrypted with the application key; two-step secrets are encrypted. In progress
Encryption in transit
CC6.7
The service is only offered over HTTPS, with secure cookies and HSTS. In progress
Data disposed of on schedule
C1.2
Retention periods are set per kind of data and a daily job deletes what is past them. In progress
Data inventory (records of processing)
C1.1
What personal and confidential data is processed, why, where and for how long (GDPR Art. 30). In progress

Privacy and GDPR

  • Your rights are self-service under Account → Privacy: download your data (JSON and CSV), correct it, restrict or object to optional processing, and erase your account. Requests that need us are answered within 30 days.
  • We keep records of processing (GDPR Art. 30), retention periods per kind of data with automatic deletion, and a breach register that tracks the 72-hour notification deadline.
  • 1 sub-processor(s) are listed on our sub-processors page. Workspace owners can review and accept our data processing agreement.
  • Optional cookies load only after consent; you can change your choice at any time with Cookie settings.

More detail on how the application itself is built is on the security page. To report a vulnerability, see Report a vulnerability.