SOC2C

Is this your company? Buyers are checking Wishbox here. Claim duve.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Wishbox logo

Wishbox

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Wishbox is SOC 2 Type II compliant. Wishbox also holds ISO 27001, and ISO 27701.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Duve is revolutionizing guest experience by offering a truly personalized guest experience suite. Duve helps hoteliers create a tailored and digital journey for each and every guest - from online check-in flows that meet the exact needs of each guest, to a web-based guest app with relevant content in the guests' native language, to personalized upsells that increase revenue potential and satisfaction of each guest. By partnering with more than 150 integration partners, across all major PMS’s, OTA’s, PSP’s, Digital Key providers and 3rd-party vendors, Duve helps transform the way guest experien

Compliance & infrastructure

Hosting
AWS
Data handled
Customer personally identifiable informationEmployee personally identifiable information

Documents

3

Subprocessors

7
  • A
    Amazon Web Services · Infrastructure Sub-processors
    EU
  • G
    Google Workspace · Infrastructure Sub-processors
    USA
  • S
    Stripe · Service Specific - Credit card payment processing
    EU
  • T
    Twilio · Service Specific - Whatsapp & SMS Messaging
    USA
  • D
    DeepL · Service Specific - Translation Services
    EU
  • O
    Open AI · Service Specific - DuveAI Add-on
    USA
  • Z
    Zendesk · Service Specific - Whatsapp Messaging
    EU

Compliance leadership

The person who leads Wishbox's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Wishbox's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

SOC 2 Type II Achieved – 17 September 2025Nov 2025

We’re proud to share that Duve has successfully achieved SOC 2 Type II compliance as of 17 September 2025, underscoring our commitment to the highest standards of data security, privacy, and reliability for our hotel partners worldwide. Independently tested and attested by PrescientSecurity, this certification confirms that Duve’s controls were designed and operated effectively over the audit period, validating the secure and trustworthy experiences we deliver at scale. Our SOC 2 Type II report is available under NDA—please contact your Duve representative to request access.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Wishbox SOC 2 compliant?
Wishbox is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Wishbox ISO 27001 certified?
According to Wishbox's public trust center, Wishbox is ISO 27001 certified. On SOC2C this listing is Listed.
Is Wishbox ISO 27701 certified?
According to Wishbox's public trust center, Wishbox is ISO 27701 certified. On SOC2C this listing is Listed.
Is Wishbox SOC 2 Type I or Type II?
Wishbox is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Wishbox's SOC 2 for a vendor risk assessment?
Yes. Wishbox's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.