SOC2C

Is this your company? Buyers are checking Driver here. Claim driver.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Driver logo

Driver

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Driver is SOC 2 Type II compliant.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Driver is an automated documentation platform that helps busy teams understand and document their code so engineers can spend their time building extraordinary products.

Compliance & infrastructure

Hosting
AWS
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

1

Subprocessors

7
  • A
    Amazon Web Services · Infrastructure Hosting
  • O
    OpenAI · Application AI Functionality
  • A
    Auth0 · Authentication & Authorization
  • H
    HubSpot · Email Marketing
  • V
    Vercel · Web Hosting
  • S
    Sentry · Error Monitoring
  • P
    PostHog · Product Analytics

Compliance leadership

The person who leads Driver's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Driver's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Driver's Latest SOC 2 Type II is now AvailableJul 2025

We are excited to announce that Driver has successfully completed another System and Organization Controls (SOC) 2 Type II audit. A SOC 2 Type II report describes a service organization's systems, whether the design of specified controls meets the relevant trust services categories, and assesses the effectiveness of those controls over a specified period of time. Driver's SOC 2 Type II report did not have any noted exceptions and was therefore issued with a “clean” audit opinion from Johanson Group LLP.

Driver's SOC 2 Type II is now availableJun 2024

We are excited to announce that Driver has successfully completed a System and Organization Controls (SOC) 2 Type II audit. A SOC 2 Type II report describes a service organization's systems, whether the design of specified controls meets the relevant trust services categories, and assesses the effectiveness of those controls over a specified period of time. Driver's SOC 2 Type II report did not have any noted exceptions and was therefore issued with a “clean” audit opinion from Johanson Group LLP.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Other certifications
    List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Driver SOC 2 compliant?
Driver is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Driver SOC 2 Type I or Type II?
Driver is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Driver's SOC 2 for a vendor risk assessment?
Yes. Driver's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Driver penetration tested?
Driver hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Driver secure?
Security isn't a single yes/no, but Driver is SOC 2 Type II compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.

Answers published by Driver

Reproduced from Driver's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How does Driver work?
At Driver, we harness Large Language Models (LLMs) to write detailed documentation from source code and enable interactive experiences for exploring source code assets. Driver is meticulously crafted to ensure a seamless, secure, and efficient integration with your existing codebase. Here's a detailed overview: - Connecting to Your Codebase: We utilize advanced encryption protocols during data transfer, ensuring your code remains confidential as it moves from your repositories to our platform. - Chunking Code into Smaller Pieces: By segmenting the code into smaller units, we ensure a granular level of analysis. This not only enhances the accuracy of the documentation but also minimizes the exposure of any single piece of your software. - Sending Code to LLMs: The segmented code is processed by LLMs in a secure environment, isolated from external threats.
Do I own my data and outputs?
- You always own your data and outputs - We will never use your data to train AI models - You can request deletion at any time, and we’ll erase your data within 10 business days
How does Driver protect my data?
- SOC 2 Type II certification - Third-party penetration testing - Platform tested to prevent malware, spyware, or other “unauthorized code” - Industry-standard safeguards against unauthorized access or alteration of your data
What deployment options does Driver offer?
- Cost-effective and rapidly deployable multi-tenant SaaS - Single-tenant SaaS with strict access restrictions - Custom options for enterprise scaling
How is Driver deployed?
Driver offers multiple deployment options to suit your specific security needs and infrastructure requirements. Typically, customers begin with our multi-tenant managed service and scale with our single-tenant managed service. Multi-tenant Managed Service - our default offering provides a cost-effective, rapidly deployable solution: - Secure hosting with strict data isolation between customers - Quick setup and immediate access to the latest features - Available in both US \[and EU\] regions for data residency and compliance purposes - Optional Enterprise SSO capabilities for seamless integration with your existing authentication systems Single-tenant Managed Service - for organizations requiring an extra layer of isolation: - Dedicated AWS account, infrastructure, and data storage for your organization - Enhanced security with the option for PrivateLink connectivity - Choice of US or EU regions for data residency and compliance purposes - Ideal for enterprises with stringent data isolation requirements