SOC2C

Is this your company? Buyers are checking Adora here. Claim adora.so free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Adora logo

Adora

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Adora is SOC 2 Type II compliant. Adora also holds HIPAA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Trust and transparency are core to how we build at Adora. We’re committed to protecting your data through robust security practices, reliable infrastructure, and thoughtful privacy and compliance standards. Keeping your information safe is foundational to how we operate every day.

Compliance & infrastructure

Hosting
AWS

Documents

3

Subprocessors

4
  • A
    Amazon Web Services · Cloud provider
  • S
    Supabase · Cloud provider
  • C
    Clickhouse
  • O
    OpenAI · Engineering

Compliance leadership

The person who leads Adora's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Adora's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Adora SOC 2 compliant?
Adora is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Adora HIPAA compliant?
According to Adora's public trust center, Adora is HIPAA compliant. On SOC2C this listing is Listed.
Is Adora SOC 2 Type I or Type II?
Adora is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Adora's SOC 2 for a vendor risk assessment?
Yes. Adora's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Adora penetration tested?
Adora hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by Adora

Reproduced from Adora's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

What data does Adora capture?
Adora takes privacy seriously and provides you with controls to allow or block what is captured in the end user’s browser. There are three primary privacy control features to manage data capture: masking, blocking, and URL management. By default, the Adora snippet does the following: - Masks all input fields, except for those with the CSS class `adora-unmask`. - Masks all HTML elements with the CSS class `adora-mask`. - Blocks all HTML elements with the CSS class `adora-block`. - Captures data only on pages where the snippet is installed, or where the URL is explicitly allowlisted. It also respects URL blocklists.
How does Adora treat my data?
Privacy is a core value at Adora. We provide robust controls to ensure you capture only what you need and nothing more. Our privacy controls give you full authority over the data being sent: - Adora operates only on pages where the snippet is explicitly installed. - All input elements are masked by default. - You can configure additional elements to mask or block using `adora-mask` or `adora-block`. For guidance on managing your privacy settings, refer to Privacy Controls.
Does Adora use cookies?
By default Adora doesn’t use any cookies. However, we do support tracking across subdomains, which requires the use of a first party cookie. This is setup on a case-by-case basis when requested by customers. If you want to link sessions between different subdomains (e.g. www.adora.so and app.adora.so) please reach out to us via slack.
How is user data sent and stored?
Session data captured in the end user’s browser is transmitted securely via HTTPS and stored with encryption at rest. Adora does not capture images or screenshots directly from the client browser. Instead, only a stream of events—representing HTML and CSS changes—is recorded. These events adhere to the configured Privacy Controls to prevent the transmission of unwanted data.
Deleting user data
Reach out to [privacy@adora.so](mailto:privacy@adora.so) with something identifiable (e.g. ip address or uid) and we’ll delete everything associated with that user.