Is this your company?Buyers are checking Driver here. Claim driver.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Driver is an automated documentation platform that helps busy teams understand and document their code so engineers can spend their time building extraordinary products.
Driver's Latest SOC 2 Type II is now AvailableJul 2025
We are excited to announce that Driver has successfully completed another System and Organization Controls (SOC) 2 Type II audit. A SOC 2 Type II report describes a service organization's systems, whether the design of specified controls meets the relevant trust services categories, and assesses the effectiveness of those controls over a specified period of time. Driver's SOC 2 Type II report did not have any noted exceptions and was therefore issued with a “clean” audit opinion from Johanson Group LLP.
Driver's SOC 2 Type II is now availableJun 2024
We are excited to announce that Driver has successfully completed a System and Organization Controls (SOC) 2 Type II audit. A SOC 2 Type II report describes a service organization's systems, whether the design of specified controls meets the relevant trust services categories, and assesses the effectiveness of those controls over a specified period of time. Driver's SOC 2 Type II report did not have any noted exceptions and was therefore issued with a “clean” audit opinion from Johanson Group LLP.
This listing is partial
6/11 details · 55%
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Other certifications
List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Driver SOC 2 compliant?
Driver is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Driver SOC 2 Type I or Type II?
Driver is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Driver's SOC 2 for a vendor risk assessment?
Yes. Driver's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Driver penetration tested?
Driver hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Driver secure?
Security isn't a single yes/no, but Driver is SOC 2 Type II compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Driver have a bug bounty or vulnerability disclosure program?
Driver hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@driver.ai or via a /security page (Driver lists a security contact).
Who are Driver's subprocessors?
Driver lists 7 subprocessors on its trust center, including Amazon Web Services, OpenAI, Auth0, HubSpot, Vercel. Buyers use this for fourth-party risk review.
Where does Driver host or store data?
Driver hosts on AWS, and handles Customer personally identifiable information, Employee personally identifiable information, Credit card information, Personal health information. Data residency details are on its trust center.
Where is Driver's trust center or security page?
Driver's trust center is at https://trust.driver.ai. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
How does Driver work?
At Driver, we harness Large Language Models (LLMs) to write detailed documentation from source code and enable interactive experiences for exploring source code assets. Driver is meticulously crafted to ensure a seamless, secure, and efficient integration with your existing codebase. Here's a detailed overview: - Connecting to Your Codebase: We utilize advanced encryption protocols during data transfer, ensuring your code remains confidential as it moves from your repositories to our platform. - Chunking Code into Smaller Pieces: By segmenting the code into smaller units, we ensure a granular level of analysis. This not only enhances the accuracy of the documentation but also minimizes the exposure of any single piece of your software. - Sending Code to LLMs: The segmented code is processed by LLMs in a secure environment, isolated from external threats.
Do I own my data and outputs?
- You always own your data and outputs - We will never use your data to train AI models - You can request deletion at any time, and we’ll erase your data within 10 business days
How does Driver protect my data?
- SOC 2 Type II certification - Third-party penetration testing - Platform tested to prevent malware, spyware, or other “unauthorized code” - Industry-standard safeguards against unauthorized access or alteration of your data
What deployment options does Driver offer?
- Cost-effective and rapidly deployable multi-tenant SaaS - Single-tenant SaaS with strict access restrictions - Custom options for enterprise scaling
How is Driver deployed?
Driver offers multiple deployment options to suit your specific security needs and infrastructure requirements. Typically, customers begin with our multi-tenant managed service and scale with our single-tenant managed service. Multi-tenant Managed Service - our default offering provides a cost-effective, rapidly deployable solution: - Secure hosting with strict data isolation between customers - Quick setup and immediate access to the latest features - Available in both US \[and EU\] regions for data residency and compliance purposes - Optional Enterprise SSO capabilities for seamless integration with your existing authentication systems Single-tenant Managed Service - for organizations requiring an extra layer of isolation: - Dedicated AWS account, infrastructure, and data storage for your organization - Enhanced security with the option for PrivateLink connectivity - Choice of US or EU regions for data residency and compliance purposes - Ideal for enterprises with stringent data isolation requirements
How is our proprietary code protected?
Your proprietary code is protected through strict access controls, data encryption during transfer and storage, and continuous monitoring for any unauthorized access, all of which are part of our SOC 2 Type II compliance protocols.
How do you handle AI model training? Is our code used to train models?
No. We do not use your IP to train large language models.
Does Driver encrypt data at rest?
Customer data is encrypted at rest.
How does Driver encrypt data in-transit?
Driver uses TLS 1.2 or higher everywhere data is transmitted over potentially insecure networks. Server TLS keys and certificates are managed by AWS and deployed via Application Load Balancers.
Where are your servers located?
Driver's servers are located in AWS, with options for data residency in the US or EU regions.
Can you meet enterprise security/legal requirements?
Yes, Driver is designed to meet enterprise security and legal requirements through flexible deployment options tailored to your security needs. With our multi-tenant managed service, you benefit from secure hosting with strict data isolation and options for enterprise SSO and data residency in the US or EU, all in a cost-effective solution. For organizations with stricter data isolation needs, our single-tenant managed service provides a dedicated AWS environment with isolated databases, PrivateLink connectivity, and dedicated authentication controls, also available in US and EU regions. This setup ensures a high level of data separation and is ideal for enterprises with stringent security requirements.
How do you handle different data classification requirements?
Driver handles different data classification requirements by offering a flexible deployment approach that aligns with your security needs as they evolve. Typically, customers begin with our multi-tenant managed service. As security requirements grow, customers can scale to our single-tenant managed service. This setup supports enhanced data classification needs with complete control over data handling, storage, and transmission, which is ideal for organizations with stringent data separation and regulatory requirements.