SOC2C

Is this your company? Buyers are checking Float Schedule here. Claim float.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Float Schedule logo

Float Schedule

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Float Schedule is SOC 2 Type I compliant. Float Schedule also holds GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Float Service Organization ("Float") provides tooling for project management. Including time tracking, forecasting and reports. The Company was founded in 2012 to provide project management services. You can view our system status at [status.float.com](https://status.float.com)

Compliance & infrastructure

Hosting
GCP
Data handled
Credit card informationPersonal health informationNames and Email Addresses

Subprocessors

17
  • G
    Google Cloud Platform · Application operation
    United States
  • D
    Datadog · Used for platform operation stability monitoring.
    United States
  • I
    Intercom · Support operations
    United States
  • M
    Mailer Lite · Customer communications
    United States
  • C
    CloudAQMP · Data streaming for platform operation
    United States
  • R
    Recurly · Customer billing and notifications
    United States
  • M
    MongoDB Atlas · Database services for platform operations
    United States
  • A
    Aiven · Data storage and streaming for application operations
    United States
  • G
    Google Workspace · Emails and documentation
    United States
  • G
    Gong · Sales engagement management
    United States
  • B
    Braintree · Used for taking payments for Float.
    United States
  • N
    Neo4j · Data storage for application operations
    United States
Show all 17 subprocessors
  • N
    Notion · Internal documentation, planning and issue tracking.
    United States
  • R
    Rollbar · Used for platform operation stability monitoring.
    United States
  • P
    PostHog · Used to get product feedback from customers.
    United States
  • M
    MongoDB · Data storage for application operations
    United States
  • L
    Launch Darkly · Platform operation
    United States

Compliance leadership

The person who leads Float Schedule's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Float Schedule's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Updates to; Privacy Policy, Terms of Use, Data Processing AgreementMar 2026

We’ve updated our Terms of Use, Privacy Policy, Data Processing Agreement, and list of sub-processors. These updates reflect our ongoing commitment to security, privacy, and transparency. They also lay the groundwork for supporting future AI capabilities and evolving regulatory requirements—while keeping your data protected and your trust at the center of how we operate. You can review the updated documents here: - Privacy Policy - Terms of Use - Data Processing Agreement --- ## A Summary of Changes - AI usage clarification - The new DPA explicitly states that customer data will not be used to train AI models and will only be used to generate requested outputs where AI features exist. - Expanded security commitments - Additional controls now documented including: - encryption standards - backup and disaster recovery - vulnerability scanning and penetration testing. - More detailed sub-processor list - Additional vendors added (e.g., Google Workspace, HubSpot, Gong, Notion, Posthog, Sentry). - Existing vendors retained. - Stronger safeguards for international transfers - Explicit reference that sub-processors outside the EEA/UK must use DPF or SCC transfer mechanisms. - Audit clarification - The new DPA clarifies that audits may be performed no more than once per year and in a remote-first manner. Privacy Policy Changes ---------------------- - Added AI transparency - New…

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Float Schedule SOC 2 compliant?
Float Schedule is SOC 2 Type I compliant. On SOC2C this listing is Listed.
Is Float Schedule GDPR compliant?
According to Float Schedule's public trust center, Float Schedule is GDPR compliant. On SOC2C this listing is Listed.
Is Float Schedule SOC 2 Type I or Type II?
Float Schedule is SOC 2 Type I compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Float Schedule's SOC 2 for a vendor risk assessment?
Yes. Float Schedule's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Float Schedule penetration tested?
Float Schedule hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Business & Industrial peers that completed SOC 2