Is this your company?Buyers are checking Cobee here. Claim cobee.io free to control the listing, earn the badge buyers trust, and see who's evaluating you.
SOC2C shows the verified essentials. 7 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Subprocessors
List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
Hosting
Add where you host (AWS, GCP, Azure) and data residency.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Cobee SOC 2 compliant?
Cobee is SOC 2 compliant. On SOC2C this listing is Listed.
Is Cobee ISO 27001 certified?
According to Cobee's public trust center, Cobee is ISO 27001 certified. On SOC2C this listing is Listed.
Is Cobee GDPR compliant?
According to Cobee's public trust center, Cobee is GDPR compliant. On SOC2C this listing is Listed.
Can I use Cobee's SOC 2 for a vendor risk assessment?
Yes. Cobee's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Cobee penetration tested?
Cobee hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Cobee secure?
Security isn't a single yes/no, but Cobee is SOC 2 compliant and holds ISO 27001, GDPR. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Cobee have a bug bounty or vulnerability disclosure program?
Cobee hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@cobee.io or via a /security page (Cobee lists a security contact).
Who are Cobee's subprocessors?
Cobee's subprocessors aren't listed on SOC2C yet. The company can add them so buyers can assess fourth-party risk.
Where does Cobee host or store data?
Cobee's hosting and data-residency details aren't listed on SOC2C yet. The company can add where it hosts (AWS, GCP, Azure) and which data it handles.
Where is Cobee's trust center or security page?
Cobee's trust center is at https://trust.cobee.io. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
How does our users identify and authenticate himself to the solution?
Our users access the Cobee platform through 3 possible access methods: - Email/Password: Via the email provided by our clients to Cobee, and a password generated by the user himself when receiving the invitation. This procedure is identical for platform administrators. - Google: It is possible to use Google as authentication method as long as our clients uses Google as mail server. - Apple: It is possible to use Apple as authentication method as long as the user has set up email in his iCloud account. - The Cobee platform supports a fourth access method (SSO) via identification with the company's access directory using the SAML protocol. This access method is exclusive for companies that require it and needs additional configuration by the company and Cobee. In case of selecting this authentication method, this would be the only one allowed to users, overriding the other three.
How are the roles available in the application?
There are 3 types of roles available: - Owner: Has full access to the company Dashboard and can manage other roles, with no exceptions. - Administrator: Has full access to the company Dashboard, except employee salaries visualization. They can also manage other roles, except Owners. - Finance: Has just access to My account and billing section (in case it is active for the company). They cannot manage roles. Regading access management, just Owners and Administrators are able to manage Cobee accesses, following the rules defined. This process is under our clients reponsabilitity and our internal agents just acts in case of needed. - Users rights and last connection information: Roles visualization is available for Owners and Administrators from the Dashboard. Regarding las connection, Cobee has this information but is not available for the company.
Describe your authentication and password Policy
Authentication of a user is carried out using a unique identifier. The password policy respects the following rules: - passwords expire after a maximum of 180 days - 14 characters minimum for standard accounts and administrators and technical accounts. - Passwords must contain lowercase, uppercase, numbers and special characters - Must not contain "patterns" (dictionary words, dates, names, first names, etc. even replacing characters with similar characters...) An SSO is set up and a two-factor authentication based on sending a code in via SMS, or Google Autenticator Account management is centralized in a directory Google Workspace.
What are the different levels of classification of the sensitivity of information at Cobee?
Public, Internal, Confidential and Restricted. Our client information is tagged as Confidential.
Is the sensitive data of the digital solution encrypted at rest? If yes by what method?
Yes, at rest AES256
What are the encryption methods for data handled in the solution when in transit over a public network, including for APIs
TLS 1.2
Describe how Cobee manages encryption keys: encryption at rest and in transit, storage, rotation, access management
We follow the AWS best practices and we have the following instances to manage secrets, passwords and Keys: Secrent Manager, Certificate Manager and KMS
What is the secure deletion method for our clients data on end-of-life media? What standard does the Cobeer refer to?
Secure Deletion of Customer Data. If you terminate a MongoDB Atlas Cluster, it will become unavailable to you immediately and any Cloud Backup associated with that MongoDB Atlas Cluster will be terminated. MongoDB may retain a copy of the Customer Data stored in the terminated MongoDB Atlas Cluster for up to 5 days. If you terminate Cloud Backups, all snapshots will become unavailable to you immediately and it may take up to 24 hours for the Customer Data contained in the snapshots to become unrecoverable. When you terminate a MongoDB Atlas Project, the master key used to encrypt Customer Data is securely wiped, rendering all Customer Data effectively unrecoverable
What tests or security checks does the solution undergo? In which phases of the development and production life cycle?
We have a Secure Development Policy based on SDLC, so security is involved in all phases of the development and production life cycle. We run internal security audits (black box) when mayor changes are applied and at least one external pentest every year.
What assets are included/excluded in the Cobee's IT inventory?
All assets are included with the owner, location and criticallity
How is the Cobee's infrastructure protected from the Internet (Firewall, DDOS, IDP/IDS, email gateways, network segmentation, bastion, Data Loss Prevention, etc.)
WAF and Firewall, network segmentation, ACLs, Security Groups and DLP
How does Cobee protect its users' equipment (PCs, mobile phones, etc.)
Crowstrike EDR is installed in all computers, Also a MDM is installed, there is a security policy applied (disk encrypted, updates, not admin users, ...)