SOC2C

Is this your company? Buyers are checking Infracost here. Claim infracost.io free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Infracost logo

Infracost

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Infracost is SOC 2 Type II compliant. Infracost also holds GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Infracost shifts cloud costs left and makes FinOps proactive. It sits in the engineering workflow and shows the cost impact of code changes before shipping to production. This catches costly mistakes before money has been spent. It also ensures all resources are tagged correctly and checks the code against FinOps policies, ensuring best practices are followed (e.g., GP2 volumes should be GP3, lifecycle policies). Responsible disclosure: If you believe you have found a security vulnerability within Infracost, please let us know right away. We’ll try and fix the problem as soon as possible. Do n

Compliance & infrastructure

Hosting
AWS

Documents

3

Subprocessors

18
  • A
    Amazon Web Services · Production infrastructure
    US East
  • G
    Google Workspace · Workspaces including email
    US
  • A
    Auth0 · Authentication of users
    US
  • C
    Close · Customer Relationship Management
    US
  • S
    Segment · Product analytics
    US
  • P
    Postmark · Sending user emails
    US
  • M
    Mixpanel · Product analytics
  • S
    Sentry · Error analytics
  • C
    Clearbit · Customer Relation Management
  • S
    Stripe · Payment processor
  • R
    Retool · Product analytics
  • P
    Pylon · Customer support
    US
Show all 18 subprocessors
  • L
    Linear · Collaboration
    US
  • N
    Notion · Document management
    US
  • I
    Incident.io · Incident management, used internally to detect, manage, and resolve operational
    US & EU
  • L
    LaunchDarkly · Feature flagging, enabling controlled rollout and management of product features
    US
  • A
    Anthropic · AI-powered capabilities within the product, as well as limited internal use to s
    US
  • C
    Common Room · Customer engagement and product analytics, helping us understand usage patterns
    US

Compliance leadership

The person who leads Infracost's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Infracost's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Infracost SOC 2 compliant?
Infracost is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Infracost GDPR compliant?
According to Infracost's public trust center, Infracost is GDPR compliant. On SOC2C this listing is Listed.
Is Infracost SOC 2 Type I or Type II?
Infracost is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Infracost's SOC 2 for a vendor risk assessment?
Yes. Infracost's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Infracost penetration tested?
Infracost hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.