SOC2C

Cobrief security & compliance

An overview of Cobrief's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 · Listed
FrameworksGDPR, ISO 27001
Penetration testNot listed
Subprocessors12 listed
HostingAWS, GCP, Azure
Trust centerView

Security questions about Cobrief

Is Cobrief secure?
Security isn't a single yes/no, but Cobrief is SOC 2 compliant and holds GDPR, ISO 27001. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Cobrief have a bug bounty or vulnerability disclosure program?
Cobrief hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@cobrief.no or via a /security page (Cobrief lists a security contact).
Who are Cobrief's subprocessors?
Cobrief lists 12 subprocessors on its trust center, including Auth0, Google Cloud Platform, Mailgun, Intercom, Amazon Web Services. Buyers use this for fourth-party risk review.
Where does Cobrief host or store data?
Cobrief hosts on AWS, GCP, Azure, and handles Employee personally identifiable information. Data residency details are on its trust center.
Where is Cobrief's trust center or security page?
Cobrief's trust center is at https://trust.cobrief.no. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See Cobrief's full SOC 2 profile →