SOC2C

Judge.me security & compliance

An overview of Judge.me's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 Type II · Listed
FrameworksISO 27001, SOC 2 Type II, NIST CSF, GDPR, CCPA
Penetration testNot listed
Subprocessors8 listed
HostingAWS
Trust centerView

Security questions about Judge.me

Is Judge.me secure?
Security isn't a single yes/no, but Judge.me is SOC 2 Type II compliant and holds ISO 27001, SOC 2 Type II, NIST CSF, GDPR, CCPA. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Judge.me have a bug bounty or vulnerability disclosure program?
Judge.me hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@judge.me or via a /security page (Judge.me lists a security contact).
Who are Judge.me's subprocessors?
Judge.me lists 8 subprocessors on its trust center, including Amazon Web Services, MongoDB Atlas, GitHub, Intercom, Postmark. Buyers use this for fourth-party risk review.
Where does Judge.me host or store data?
Judge.me hosts on AWS, and handles Customer personally identifiable information, Employee personally identifiable information, Credit card information, Personal health information. Data residency details are on its trust center.
Does Judge.me offer a Data Processing Agreement (DPA)?
Judge.me publishes a DPA on its trust center. You can request access through SOC2C.
Where is Judge.me's trust center or security page?
Judge.me's trust center is at https://compliance.judge.me. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See Judge.me's full SOC 2 profile →