SOC2C

Is this your company? Buyers are checking By clicking here. Claim factory.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
By clicking logo

By clicking

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

By clicking is SOC 2 Type II compliant. By clicking also holds ISO 42001, and CCPA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Welcome to our Trust Portal for Factory - your portal to understanding our unwavering commitment to data security, privacy, and compliance. Here, you can access our compliance documentation, find answers to frequently asked questions related to security and privacy, and explore our robust security practices. We believe in maintaining transparency and building trust with our customers, and this portal is designed to provide you with the information and assurance you need to feel confident in our ability to protect your data.

Compliance & infrastructure

SOC 2 Type IIISO 42001CCPA
Hosting
AWSGCPAzure
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health informationCode Metadata

Documents

7

Subprocessors

16
  • M
    Microsoft Azure · Cloud provider
  • A
    Amazon Web Services · aws
  • G
    Google Cloud Platform · gcp
  • G
    GitHub · github
  • A
    Anthropic · Processing AI requests
  • A
    Axiom · Analytics and log analysis
  • F
    Fireworks · Engineering
  • G
    Google Drive · Document management
  • M
    MongoDB · Data storage and processing
  • O
    OpenAI · Processing AI requests
  • O
    Orb · Billing
  • S
    Sentry · Analytics and log analysis
Show all 16 subprocessors
  • S
    Slack · Collaboration
  • S
    Stripe · Billing
  • V
    Vercel · Web application hosting
  • W
    WorkOS · User authentication

Compliance leadership

The person who leads By clicking's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. By clicking's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

New subprocessor: MongoDBJun 2026

We are contracting with MongoDB to store usage data.

New subprocessor: BasetenJun 2026

We are contracting with Baseten to provide AI model processing functions to our customers.

New subprocessor: Second FrontJun 2026

We are contracting with Second Front to provide FedRamp hosting for government customers.

New subprocessor: FireworksMar 2026

We have contracted with Fireworks to provide AI model processing functions to our customers.

New subprocessor: AnthropicMar 2026

We have contracted with Anthropic to provide AI model processing functions to our customers.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is By clicking SOC 2 compliant?
By clicking is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is By clicking ISO 42001 certified?
According to By clicking's public trust center, By clicking is ISO 42001 certified. On SOC2C this listing is Listed.
Is By clicking CCPA compliant?
According to By clicking's public trust center, By clicking is CCPA compliant. On SOC2C this listing is Listed.
Is By clicking SOC 2 Type I or Type II?
By clicking is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use By clicking's SOC 2 for a vendor risk assessment?
Yes. By clicking's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by By clicking

Reproduced from By clicking's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How is my code and data protected in your infrastructure?
Our infrastructure is built with security-first principles: - All infrastructure is defined as code using Terraform, ensuring consistent and secure deployments - Resources are deployed in a Virtual Private Cloud (VPC) with private subnets - Security groups strictly control access between components - All data is encrypted at rest using AWS KMS and in transit using TLS - DynamoDB tables use server-side encryption - S3 buckets are configured with strict access controls and encryption - ECS tasks run in private subnets with minimal required permissions
What security measures are in place for your deployments?
Our Kubernetes infrastructure includes: - Separate control plane and data plane clusters for isolation - Private subnets for worker nodes - IAM roles with least privilege principles - Prometheus monitoring for security metrics - Regular security patches and updates - Network policies controlling pod-to-pod communication
How do you handle logging and monitoring?
We employ comprehensive logging and monitoring: - Prometheus and Grafana for metrics monitoring - CloudWatch for AWS service monitoring - Firehose for log aggregation - Sentry for error tracking and performance monitoring - Regular log analysis for security events
What data do you collect and store?
We manage: - Repository metadata (file paths, function signatures, class definitions) - User authentication information - Organization configuration data - Usage metrics and telemetry - Session data for active users We do NOT store: - Complete source code from repositories - Sensitive credentials or secrets - Personal information beyond what's necessary for service operation
How is data isolated between organizations?
We ensure strict data isolation through: - Separate DynamoDB tables per environment - Organization-specific S3 buckets - IAM roles and policies enforcing access boundaries - Firestore security rules preventing cross-organization access - Kubernetes namespace isolation for organization workloads