Softmatica handles customer data, deal terms, and product usage for revenue teams at software companies, so it is held to the same bar those teams hold their own product to.
Every layer of Softmatica, from the database to the integrations you connect, is built with the same security posture your own product is held to.
All data is encrypted in transit with TLS 1.2+ and at rest with AES-256, including database volumes, backups, and file attachments.
Our partners undergo an independent SOC 2 Type II audit annually, covering security, availability, and confidentiality controls.
Automated daily backups are encrypted and retained on a rolling 30-day window, with point-in-time recovery for Scale and Enterprise plans.
Granular permissions control who can view, edit, or export records down to the field level, so a support rep and a finance admin see different slices of the same account.
Enterprise plans support SAML-based single sign-on and SCIM provisioning, so access follows your identity provider instead of a separate password.
Data processing agreements, data subject request tooling, and regional data residency options are available for customers operating under GDPR or CCPA.
A public, up-to-date list of every sub-processor Softmatica relies on is available on request, along with 30-day advance notice before any change.
Infrastructure is monitored around the clock for anomalous access patterns, with automated alerting routed to an on-call security engineer.
Scale and Enterprise plans carry a contractual 99.9% uptime SLA, with historical status and incident history published on our status page.
Production data is hosted in the United States by default. Enterprise customers with GDPR or data-sovereignty requirements can pin their workspace to EU-based infrastructure at no extra cost.
Encrypted daily backups are retained on a rolling 30-day window. Point-in-time recovery is available for Scale and Enterprise plans, letting you restore an account to any point in that window.
Customer Data is retained for 30 days after cancellation to allow export or reactivation, then permanently purged from production systems, with backups aging out on their normal 30-day cycle.
Enterprise workspaces authenticate through your identity provider instead of a separate Softmatica password, so access follows the same joiner/mover/leaver process your IT team already owns.
Security is a gate in the release process, not a review that happens after the fact.
New features that touch customer data or authentication get a lightweight threat model before implementation starts, reviewed by a security-minded engineer outside the feature team.
Every pull request runs through automated static analysis and dependency vulnerability scanning; known-vulnerable dependencies block merge until patched or explicitly waived.
No code reaches production without a second engineer’s review, including infrastructure-as-code changes to production environments.
Changes ship behind feature flags to a small percentage of workspaces first, with automated rollback on error-rate or latency regressions before a full release.
An independent security firm performs a full penetration test at least once a year, and findings are tracked to resolution against a fixed SLA by severity.
Softmatica runs a responsible disclosure program for security researchers. Report a suspected vulnerability to our security team and we will acknowledge it, investigate, and keep you updated until it is resolved. We do not pursue legal action against good-faith research conducted under this policy.
Production data is hosted on major cloud infrastructure providers in the United States by default, with EU data residency available for customers with GDPR requirements.
Yes, SAML-based SSO and SCIM provisioning are available on the Enterprise plan, so user access can be managed entirely through your identity provider.
Data subject access and deletion requests under GDPR or CCPA are processed through a dedicated workflow with a committed 30-day turnaround, and account owners can export or delete their own data at any time from workspace settings.
Only where necessary to run the service, such as cloud hosting and email delivery. A full sub-processor list is available on request, and customers are notified at least 30 days before any change.
Send us your questionnaire or book time with our security team, and start your trial while we get you answers.