SOC2C

Is this your company? Buyers are checking Gotrebol here. Claim gotrebol.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Gotrebol logo

Gotrebol

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Gotrebol is SOC 2 compliant. Gotrebol also holds ISO 27001.

Framework
SOC 2
Auditor
Last report
Renewal
View official trust center ↗

Compliance & infrastructure

Hosting
AWSGCPAzure

Documents

30

Subprocessors

5
  • V
    Vercel · Engineering
  • A
    Amazon Web Services · Cloud provider
  • G
    Google Cloud Platform · Cloud provider
  • M
    Microsoft Azure · Cloud provider
  • P
    PlanetScale

Compliance leadership

The person who leads Gotrebol's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Gotrebol's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Other certifications
    List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
  • Description
    Add a one-line description so buyers recognize you.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Gotrebol SOC 2 compliant?
Gotrebol is SOC 2 compliant. On SOC2C this listing is Listed.
Is Gotrebol ISO 27001 certified?
According to Gotrebol's public trust center, Gotrebol is ISO 27001 certified. On SOC2C this listing is Listed.
Can I use Gotrebol's SOC 2 for a vendor risk assessment?
Yes. Gotrebol's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Gotrebol penetration tested?
Gotrebol hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Gotrebol secure?
Security isn't a single yes/no, but Gotrebol is SOC 2 compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.

Answers published by Gotrebol

Reproduced from Gotrebol's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

¿Trébol implementa un programa de gestión de vulnerabilidades y pruebas de penetración?
Sí, nuestro programa de gestión de vulnerabilidades tecnológicas y pruebas de penetración se enfoca en identificar, analizar y mitigar riesgos de seguridad en nuestra infraestructura y aplicaciones. Realizamos pruebas de penetración de forma periódica para evaluar la efectividad de nuestras medidas de seguridad y asegurarnos de que estamos protegidos contra posibles amenazas.
¿Con qué frecuencia se hacen pruebas de penetración para la aplicación de Trébol?
Realizamos pruebas de penetración trimestralmente, y estas son llevadas a cabo por auditores externos especializados.
¿Dónde se encuentran las evidencias y resultados de las pruebas de penetración de Trébol?
Por motivos de seguridad y confidencialidad, los informes detallados de las pruebas de penetración se comparten únicamente en llamadas programadas con el personal autorizado o para informes a la CNBV. Estos informes incluyen: - Procedimientos de las pruebas. - Resultados detallados de las pruebas. - Vulnerabilidades identificadas y su severidad. - Planes de remediación y evidencia de corrección de los problemas.
¿Cuál es el último informe de pen-testing?
El último informe de pruebas de penetración fue realizado por Securily en el Q2 de 2024. Por seguridad, los resultados y las medidas tomadas están disponibles para revisión bajo solicitud y se discutirán en detalle durante una llamada programada con nuestro equipo de seguridad.
¿Cómo gestiona Trébol los análisis de riesgo?
En Trébol, el Comité de Sistema de Gestión de Seguridad de la Información (SGSI) realiza análisis y priorización de los principales riesgos de seguridad de la información de forma anual periódica, así como cuando ocurre algún cambio relevante, previamente identificado por el Líder de Gestión de Seguridad de la Información. Este proceso incluye la identificación, evaluación y mitigación de riesgos para asegurar que nuestra infraestructura y operaciones sean seguras y estén protegidas contra amenazas potenciales.

Business & Industrial peers that completed SOC 2