SOC2C

Is this your company? Buyers are checking Ledge Inc here. Claim ledge.co free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Ledge Inc logo

Ledge Inc

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Ledge Inc is SOC 2 Type II compliant. Ledge Inc also holds ISO 42001.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Ledge gives you peace of mind with enterprise-level security to ensure your critical data is secure. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about some of the measures we take to provide a secure experience on Ledge for you and your team.

Compliance & infrastructure

SOC 2 Type IIISO 42001
Hosting
AWS
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health informationBank recordsPayment Service Providers recordsERPs records

Documents

9

Subprocessors

7
  • A
    Amazon Web Services · Cloud provider
    United State
  • A
    Auth0 · Identity provider
    United State
  • C
    Cloudflare · Cloud hosting
    United State
  • M
    MongoDB Atlas · Data storage and processing
  • V
    Vercel · Engineering
  • A
    Aiven · Messaging
    United State
  • A
    Arango DB · Graph DB
    United State

Compliance leadership

The person who leads Ledge Inc's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Ledge Inc's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Ledge Inc SOC 2 compliant?
Ledge Inc is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Ledge Inc ISO 42001 certified?
According to Ledge Inc's public trust center, Ledge Inc is ISO 42001 certified. On SOC2C this listing is Listed.
Is Ledge Inc SOC 2 Type I or Type II?
Ledge Inc is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Ledge Inc's SOC 2 for a vendor risk assessment?
Yes. Ledge Inc's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Ledge Inc penetration tested?
Ledge Inc hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by Ledge Inc

Reproduced from Ledge Inc's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Do you encrypt data at rest?
Yes, we ensure the security of stored data by encrypting it at rest using industry-standard encryption protocols. This approach aligns with best practices to protect your sensitive information.
I found a security bug. Do you have an established bug bounty program?
We highly value the security of our platform and appreciate contributions from the security community. If you've identified a security vulnerability, please email us at security@ledge.co with the following details: 1. A clear description of the issue 2. The potential impact of the issue on our customers 3. Detailed steps to reproduce the issue We will review all submissions containing complete information and consider issuing a bounty for significant findings.
Do you support Single Sign-On (SSO)?
Yes, we support Single Sign-On (SSO) to streamline user access and enhance security. For setup and additional details, please contact our customer support team.
Where are your servers located?
Our servers and databases are securely hosted in the United States
How do you monitor for security breaches?
We adhere to industry best practices in security monitoring, including the utilization of advanced tools like AWS GuardDuty. Our tools continuously scan the production environment for any potential security threats. All identified issues are promptly reported to our on-call security team for immediate investigation and resolution.