SOC2C

Cundall security & compliance

An overview of Cundall's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 · Listed
FrameworksISO 27001
Penetration testNot listed
Subprocessors8 listed
HostingAWS, GCP
Trust centerView

Security questions about Cundall

Is Cundall secure?
Security isn't a single yes/no, but Cundall is SOC 2 compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Cundall have a bug bounty or vulnerability disclosure program?
Cundall hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@cundall.com or via a /security page (Cundall lists a security contact).
Who are Cundall's subprocessors?
Cundall lists 8 subprocessors on its trust center, including Microsoft, Google, Amazon Web Services, Nasuni, Newforma. Buyers use this for fourth-party risk review.
Where does Cundall host or store data?
Cundall hosts on AWS, GCP. Data residency details are on its trust center.
Where is Cundall's trust center or security page?
Cundall's trust center is at https://trust.cundall.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See Cundall's full SOC 2 profile →