SOC2C

Collective security & compliance

An overview of Collective's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 Type II · Listed
FrameworksSOC 2 Type II
Penetration testNot listed
SubprocessorsNot listed
HostingNot listed
Trust centerView

Security questions about Collective

Is Collective secure?
Security isn't a single yes/no, but Collective is SOC 2 Type II compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Collective have a bug bounty or vulnerability disclosure program?
Collective hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@collective.com or via a /security page (Collective lists a security contact).
Who are Collective's subprocessors?
Collective's subprocessors aren't listed on SOC2C yet. The company can add them so buyers can assess fourth-party risk.
Where does Collective host or store data?
Collective's hosting and data-residency details aren't listed on SOC2C yet. The company can add where it hosts (AWS, GCP, Azure) and which data it handles.
Where is Collective's trust center or security page?
Collective's trust center is at https://trust.collective.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See Collective's full SOC 2 profile →