SOC2C

Is this your company? Buyers are checking Dashworks here. Claim dashworks.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Dashworks logo

Dashworks

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Dashworks is SOC 2 Type II compliant. Dashworks also holds HIPAA, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Dashworks provides internal search for your organization. With Dashworks, your team can instantly find what they are looking for by searching across all work apps.

Compliance & infrastructure

Documents

4

Compliance leadership

The person who leads Dashworks's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Dashworks's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Subprocessors
    List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Dashworks SOC 2 compliant?
Dashworks is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Dashworks HIPAA compliant?
According to Dashworks's public trust center, Dashworks is HIPAA compliant. On SOC2C this listing is Listed.
Is Dashworks GDPR compliant?
According to Dashworks's public trust center, Dashworks is GDPR compliant. On SOC2C this listing is Listed.
Is Dashworks SOC 2 Type I or Type II?
Dashworks is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Dashworks's SOC 2 for a vendor risk assessment?
Yes. Dashworks's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by Dashworks

Reproduced from Dashworks's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Which LLM providers are used as sub-processors, and what kind of agreement is in place for each?
Dashworks uses OpenAI as LLM providers. Document snippets and user queries are sent to the providers via APIs. API policies and agreements with each provider restrict the use of data sent via APIs for any AI training purposes, and the data is retained for a maximum of 30 days.
Do you follow any open-source standards as it pertains to Security? (e.g. OWASP SAMM, ASVS, MASVS, etc.)
Yes, Dashworks follows OWASP SAMM v2.
Do you have Information Security Policies approved by management and reviewed as necessary but at least once a year?
Yes, the following Information Security Policies are approved by management and reviewed annually: Acceptable Use, Information Management, Information and Data Classification, Encryption, Change Management, Vulnerability Management, Auditing, Log Management, Monitoring & Retention, Software Development Lifecycle, Incident Management, Business Continuity, Disaster Recovery, Backup and Redundancy, Third-Party and Vendor Management, Human Resources, Identity and Access Management.
Do you currently employee an in-house Security Team? If yes, what is the team composition / focus areas? If yes, please detail the team composition / focus areas in the explanation section below.
Yes. The team is led by the CTO and has two full-time Software Engineers focused on cloud infrastructure security as well as application security (backend and frontend).
Are employees required to take security awareness training at least annually?
Yes.