Is this your company? Buyers are checking Cobee here. Claim cobee.io free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
Cobee
Sourced from public information. Not yet verified by the company.
Cobee is SOC 2 compliant. Cobee also holds ISO 27001, and GDPR.
About
The employee benefits and flexible remuneration platform that makes both company and employees love it.
Compliance & infrastructure
Compliance leadership
The person who leads Cobee's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. Cobee's penetration test vendor isn't listed yet.
Claim this profile to add it.
This listing is partial
4/11 details · 36%SOC2C shows the verified essentials. 7 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- DocumentsList the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
- SubprocessorsList your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
- HostingAdd where you host (AWS, GCP, Azure) and data residency.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Cobee SOC 2 compliant?
Is Cobee ISO 27001 certified?
Is Cobee GDPR compliant?
Can I use Cobee's SOC 2 for a vendor risk assessment?
Is Cobee penetration tested?
Is Cobee secure?
Does Cobee have a bug bounty or vulnerability disclosure program?
Who are Cobee's subprocessors?
Where does Cobee host or store data?
Where is Cobee's trust center or security page?
Answers published by Cobee
Reproduced from Cobee's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗
How does our users identify and authenticate himself to the solution?
How are the roles available in the application?
Describe your authentication and password Policy
What are the different levels of classification of the sensitivity of information at Cobee?
Is the sensitive data of the digital solution encrypted at rest? If yes by what method?
What are the encryption methods for data handled in the solution when in transit over a public network, including for APIs
Describe how Cobee manages encryption keys: encryption at rest and in transit, storage, rotation, access management
What is the secure deletion method for our clients data on end-of-life media? What standard does the Cobeer refer to?
What tests or security checks does the solution undergo? In which phases of the development and production life cycle?
What assets are included/excluded in the Cobee's IT inventory?
How is the Cobee's infrastructure protected from the Internet (Firewall, DDOS, IDP/IDS, email gateways, network segmentation, bastion, Data Loss Prevention, etc.)
How does Cobee protect its users' equipment (PCs, mobile phones, etc.)
Technology peers that completed SOC 2

Action1

ELJUN LLC

equipifi
