SOC 2 Type II
Independent audit of security, availability, and confidentiality controls over a 6-month period. Planned once we're out of beta — no audit is underway today.
Planned — post-betaGDPR
Data Processing Agreement available. Data stored in AWS us-east-2. Right to erasure supported.
Aligned — In ProgressISO 27001
Planned for 2027. Our security practices already align with ISO 27001 controls.
Planned — 2027Trust Services Criteria
SOC 2 audits evaluate controls against five Trust Services Criteria (TSC). Here's how OpsPing addresses each:
Security
Information and systems are protected against unauthorized access, unauthorized disclosure, and damage. See our Security page for full details on encryption, access controls, network security, and vulnerability management.
Availability
Information and systems are available for operation and use. Key controls: DynamoDB point-in-time backups, process supervision with automatic restart on the application host, uptime and error monitoring with alerting to our own on-call rotation, incident response runbooks, and an external status page backed by the live public status API.
Confidentiality
Information designated as confidential is protected. Key controls: bcrypt password and API-key hashing, API key scoping (read/write/delete/config), per-team roles with a custom permission matrix, hard tenant isolation with zero standing access (staff cannot read customer data), TLS via Caddy, encryption at rest in DynamoDB, and no plaintext secrets in code or config.
Processing Integrity
System processing is complete, valid, accurate, timely, and authorized. Key controls: alert deduplication (alias-based), input validation with Zod schemas on every endpoint, durable delayed and repeated notifications, and an append-only audit log recording every administrative action.
Privacy
Personal information is collected, used, retained, disclosed, and disposed of in conformity with our Privacy Policy. Key controls: data retention policies, right to deletion, data minimization (we only store what's needed for alerting), and no third-party data sharing.
Where We Stand
| Item | Status |
|---|---|
| Security controls | Implemented as described above and on our Security page; not independently audited |
| Auditor engagement | Not started |
| Type II audit period | Not started — planned after beta |
| SOC 2 Type II report | Not available |
We'd rather underpromise here. When an audit is scheduled, this page will carry real dates.
Request Our Security Package
No SOC 2 report exists yet. In the meantime, we're happy to share what we do have — completed security questionnaire responses, our DPA, the subprocessor list, and architecture overviews — under NDA where appropriate. Email security@ops-ping.com.