SOC2C

Is this your company? Buyers are checking Exalate here. Claim exalate.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Exalate logo

Exalate

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Exalate is SOC 2 compliant. Exalate also holds ISO 27001.

Framework
SOC 2
Auditor
Last report
Renewal
View official trust center ↗

About

Our mission at Exalate is to make collaboration easy across teams and company borders by providing a secure, scalable integration that bridges the gap between systems.

Compliance & infrastructure

Documents

7

Subprocessors

5
  • G
    Google LLC · Web Analytics, Cloud Hosting
    1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
  • r
    rsync.net, Inc. · Storage of encrypted off-site backup
    524 San Anselmo Ave. Suite 107, San Anselmo, CA 94960, USA
  • H
    Hubspot, Inc. · CRM
    2 Canal Park, Cambridge, MA 02141 USA
  • O
    OpenAI · Process integration scripts to identify and suggest improvements
    3180 18th Street, San Francisco, CA 94110 USA
  • D
    Datacenter United · Data Center Provider
    Haïfastraat 6, 2030 Antwerp, Belgium

Compliance leadership

The person who leads Exalate's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Exalate's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Other certifications
    List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Exalate SOC 2 compliant?
Exalate is SOC 2 compliant. On SOC2C this listing is Listed.
Is Exalate ISO 27001 certified?
According to Exalate's public trust center, Exalate is ISO 27001 certified. On SOC2C this listing is Listed.
Can I use Exalate's SOC 2 for a vendor risk assessment?
Yes. Exalate's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Exalate penetration tested?
Exalate hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Does Exalate offer a Data Processing Agreement (DPA)?
Exalate publishes a DPA on its trust center; you can request access through SOC2C.

Answers published by Exalate

Reproduced from Exalate's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

The Exalate Approach to Security
At Exalate we base our security approach on three dimensions: - Security by Design Security vulnerability scanning has been implemented at every stage of the development, deployment, and operation of the solution. This scanning is based on the solutions provided by Aikido, which allow highlighting the security problems from the moment a developer types a line of code. - Advanced Endpoint detection and response (EDR) monitored by a 24/7 SOC EDR is implemented through a combination of the Palo Alto Cortex XDR solution, a 24/7 manned SOC for addressing incidents and vulnerabilities, and the Security Command Center to guard the Exalate cloud environment. - Process and policies focused on increasing the security awareness of the whole team All policies related to the ISO27001 standard have been implemented and are controlled by various processes. Roles and responsibilities are defined and assigned to various people in the team. These policies include: - Acceptable use - Privacy and Employee privacy - Security awareness training for all the employees - HR recruitment - The Incident, Vulnerability, and Change management - Risk management While we can address the specific security concerns customers might have based on their use cases, the following is a list of the most commonly asked questions.
Is Exalate ISO certified?
Exalate is ISO27001:2022 certified. This means that all the conditions for achieving this certification have been implemented. Evidence of the auditing process and the certificate can be provided upon request.
Is Exalate SOC2 compliant?
As part of our ongoing improvements to our security program, we will soon proceed with the SOC2 certification.
Is Exalate GDPR Compliant?
Exalate has its HQ in Europe (Belgium) and therefore complies with all GDPR-related legislation.
What is the benefit of Exalate's single-tenant architecture compared to a multi-tenant one?
A single-tenant application, in the context of integration software, is an application that is related to only one system. A multi-tenant application on the other hand allows using one infrastructure to connect with multiple systems. So, whenever considering an integration solution, one should pay attention to the tenancy of the proposition. All software has bugs, either because of improper development, configuration mistakes, or any other reason. The recent breaches at LastPass and Octa show that protecting information is a Herculean task. Integration software is more complex as it needs to take care of many diverse aspects and information paths. To minimize the risk of information leakage, a single-tenant architecture is a much better option as it allows us to contain information leaks at the infrastructure level. When an Exalate node is deployed on the Exalate Cloud, it is running inside a ‘Kubernetes pod’ that is configured to ensure no information can leak. The maintenance of this Exalate Cloud is fully based on the principles of ‘Infrastructure as Code’. There is no manual configuration for the environment.