[ SECURITY & TRUST ]

Security your engineering team will actually sign off on

Softmatica handles customer data, deal terms, and product usage for revenue teams at software companies, so it is held to the same bar those teams hold their own product to.

SOC 2 Type II Ready GDPR ready CCPA ready 99.9% uptime SLA Daily encrypted backups
[ HOW WE PROTECT YOUR DATA ]

The technical measures behind the badges

Every layer of Softmatica, from the database to the integrations you connect, is built with the same security posture your own product is held to.

Encryption everywhere

All data is encrypted in transit with TLS 1.2+ and at rest with AES-256, including database volumes, backups, and file attachments.

SOC 2 Type II Ready

Our partners undergo an independent SOC 2 Type II audit annually, covering security, availability, and confidentiality controls.

Daily encrypted backups

Automated daily backups are encrypted and retained on a rolling 30-day window, with point-in-time recovery for Scale and Enterprise plans.

Role-based access control

Granular permissions control who can view, edit, or export records down to the field level, so a support rep and a finance admin see different slices of the same account.

SSO & SCIM on Enterprise

Enterprise plans support SAML-based single sign-on and SCIM provisioning, so access follows your identity provider instead of a separate password.

GDPR & CCPA compliant

Data processing agreements, data subject request tooling, and regional data residency options are available for customers operating under GDPR or CCPA.

Sub-processor transparency

A public, up-to-date list of every sub-processor Softmatica relies on is available on request, along with 30-day advance notice before any change.

Continuous monitoring

Infrastructure is monitored around the clock for anomalous access patterns, with automated alerting routed to an on-call security engineer.

99.9% uptime commitment

Scale and Enterprise plans carry a contractual 99.9% uptime SLA, with historical status and incident history published on our status page.

[ DATA RESIDENCY & RETENTION ]

Where your data lives, and how long we keep it

Regional data residency

Production data is hosted in the United States by default. Enterprise customers with GDPR or data-sovereignty requirements can pin their workspace to EU-based infrastructure at no extra cost.

Backup retention

Encrypted daily backups are retained on a rolling 30-day window. Point-in-time recovery is available for Scale and Enterprise plans, letting you restore an account to any point in that window.

Post-cancellation retention

Customer Data is retained for 30 days after cancellation to allow export or reactivation, then permanently purged from production systems, with backups aging out on their normal 30-day cycle.

[ IDENTITY & ACCESS ]

SSO that fits the identity stack you already run

Enterprise workspaces authenticate through your identity provider instead of a separate Softmatica password, so access follows the same joiner/mover/leaver process your IT team already owns.

  • SAML 2.0: works with Okta, Azure AD/Entra ID, OneLogin, and any standards-based SAML identity provider.
  • OpenID Connect (OIDC): token-based SSO for providers that prefer OIDC over SAML, including Google Workspace.
  • SCIM provisioning: automatic user creation, role assignment, and deprovisioning as people join, change teams, or leave.
  • LDAP-backed directories: supported via SAML/OIDC bridge for customers running on-prem directory services.
Workspace · SSO settings
ProtocolSAML 2.0
ProvisioningSCIM, auto-deprovision
Enforced forAll workspace members
Directory syncEvery 15 minutes
[ HOW WE BUILD ]

A security-reviewed development lifecycle

Security is a gate in the release process, not a review that happens after the fact.

01

Threat modeling at design time

New features that touch customer data or authentication get a lightweight threat model before implementation starts, reviewed by a security-minded engineer outside the feature team.

02

Static analysis & dependency scanning

Every pull request runs through automated static analysis and dependency vulnerability scanning; known-vulnerable dependencies block merge until patched or explicitly waived.

03

Peer review on every change

No code reaches production without a second engineer’s review, including infrastructure-as-code changes to production environments.

04

Staged rollouts & monitoring

Changes ship behind feature flags to a small percentage of workspaces first, with automated rollback on error-rate or latency regressions before a full release.

05

Annual third-party penetration testing

An independent security firm performs a full penetration test at least once a year, and findings are tracked to resolution against a fixed SLA by severity.

[ RESPONSIBLE DISCLOSURE ]

Found a vulnerability? Tell us first.

Softmatica runs a responsible disclosure program for security researchers. Report a suspected vulnerability to our security team and we will acknowledge it, investigate, and keep you updated until it is resolved. We do not pursue legal action against good-faith research conducted under this policy.

  • Acknowledgment within 24 hours of a report
  • Regular status updates until the issue is resolved
  • Credit in our security acknowledgments, if you want it
security@softmatica.net
Trust · Status overview
SOC 2 Type II ReadyAudit in progress
Uptime, trailing 90 days99.97%
EncryptionTLS 1.2+ / AES-256
Backup frequencyDaily, 30-day retention
Disclosure acknowledgmentWithin 24 hours
[ FAQ ]

Security questions we hear most

Production data is hosted on major cloud infrastructure providers in the United States by default, with EU data residency available for customers with GDPR requirements.

Yes, SAML-based SSO and SCIM provisioning are available on the Enterprise plan, so user access can be managed entirely through your identity provider.

Data subject access and deletion requests under GDPR or CCPA are processed through a dedicated workflow with a committed 30-day turnaround, and account owners can export or delete their own data at any time from workspace settings.

Only where necessary to run the service, such as cloud hosting and email delivery. A full sub-processor list is available on request, and customers are notified at least 30 days before any change.

Have a security review in progress?

Send us your questionnaire or book time with our security team, and start your trial while we get you answers.

Done