SOC 2 Type II

Independent audit of security, availability, and confidentiality controls over a 6-month period. Planned once we're out of beta — no audit is underway today.

Planned — post-beta

GDPR

Data Processing Agreement available. Data stored in AWS us-east-2. Right to erasure supported.

Aligned — In Progress

ISO 27001

Planned for 2027. Our security practices already align with ISO 27001 controls.

Planned — 2027

Trust Services Criteria

SOC 2 audits evaluate controls against five Trust Services Criteria (TSC). Here's how OpsPing addresses each:

Security

Information and systems are protected against unauthorized access, unauthorized disclosure, and damage. See our Security page for full details on encryption, access controls, network security, and vulnerability management.

Availability

Information and systems are available for operation and use. Key controls: DynamoDB point-in-time backups, process supervision with automatic restart on the application host, uptime and error monitoring with alerting to our own on-call rotation, incident response runbooks, and an external status page backed by the live public status API.

Confidentiality

Information designated as confidential is protected. Key controls: bcrypt password and API-key hashing, API key scoping (read/write/delete/config), per-team roles with a custom permission matrix, hard tenant isolation with zero standing access (staff cannot read customer data), TLS via Caddy, encryption at rest in DynamoDB, and no plaintext secrets in code or config.

Processing Integrity

System processing is complete, valid, accurate, timely, and authorized. Key controls: alert deduplication (alias-based), input validation with Zod schemas on every endpoint, durable delayed and repeated notifications, and an append-only audit log recording every administrative action.

Privacy

Personal information is collected, used, retained, disclosed, and disposed of in conformity with our Privacy Policy. Key controls: data retention policies, right to deletion, data minimization (we only store what's needed for alerting), and no third-party data sharing.

Where We Stand

ItemStatus
Security controlsImplemented as described above and on our Security page; not independently audited
Auditor engagementNot started
Type II audit periodNot started — planned after beta
SOC 2 Type II reportNot available

We'd rather underpromise here. When an audit is scheduled, this page will carry real dates.

Request Our Security Package

No SOC 2 report exists yet. In the meantime, we're happy to share what we do have — completed security questionnaire responses, our DPA, the subprocessor list, and architecture overviews — under NDA where appropriate. Email security@ops-ping.com.