Is this your company?Buyers are checking LIFELENZ here. Claim lifelenz.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
At LifeLenz, we recognize the importance of safeguarding our clients' data. That is why we adhere to the highest standards of security at every level of our product and operations. This includes prioritizing the protection of this information by implementing robust security controls and measures designed to secure all aspects of our services. LifeLenz is committed to ensuring the security, confidentiality, and integrity of our clients’ information, in adherence with industry best practices, regulatory requirements, and the use of advanced technologies which prevent unauthorized access to this
LifeLenz Achieves SOC 2 Type 2 and SOC 3 Compliance 2025Mar 2026
SOC 2 Type 2 & SOC 3 2025 Reports Available LifeLenz is pleased to announce the successful completion of our annual SOC 2 Type 2 and SOC 3 assessments. These independent audits continue to validate our commitment to maintaining the highest standards of security, availability, and confidentiality. What This Means The SOC 2 Type 2 report demonstrates our sustained adherence to industry-leading security practices, confirming that our controls are effectively designed and operating over time. The SOC 3 report provides a publicly available summary of our compliance with these standards. Access Our Reports The latest SOC 2 Type 2 and SOC 3 reports are now available on our Trust Center: https://trust.lifelenz.com/ We remain committed to transparency and security in everything we do. For any questions or additional information, please contact us.
SOC 2 Type 2; SOC 3 2024 Reports AvailableFeb 2025
LifeLenz Achieves SOC 2 Type 2 and SOC 3 Compliance LifeLenz is pleased to announce the successful completion of our SOC 2 Type 2 and SOC 3 assessments. These independent audits validate our commitment to maintaining the highest standards of security, availability, and confidentiality. What This Means The SOC 2 Type 2 report demonstrates our ongoing adherence to industry-leading security practices, ensuring that our controls are effectively designed and operating over time. The SOC 3 report provides a publicly available summary of our compliance with these standards. Access Our Reports The latest SOC 2 Type 2 and SOC 3 reports are now available on our Trust Center. We remain committed to transparency and security in everything we do. For any questions or additional information, please contact us.
This listing is partial
6/11 details · 55%
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is LIFELENZ SOC 2 compliant?
LIFELENZ is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is LIFELENZ GDPR compliant?
According to LIFELENZ's public trust center, LIFELENZ is GDPR compliant. On SOC2C this listing is Listed.
Is LIFELENZ NIST CSF compliant?
According to LIFELENZ's public trust center, LIFELENZ is NIST CSF compliant. On SOC2C this listing is Listed.
Is LIFELENZ SOC 2 Type I or Type II?
LIFELENZ is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use LIFELENZ's SOC 2 for a vendor risk assessment?
Yes. LIFELENZ's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is LIFELENZ penetration tested?
LIFELENZ hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is LIFELENZ secure?
Security isn't a single yes/no, but LIFELENZ is SOC 2 Type II compliant and holds SOC 2 Type II, GDPR, NIST CSF. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does LIFELENZ have a bug bounty or vulnerability disclosure program?
LIFELENZ hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@lifelenz.com or via a /security page.
Who are LIFELENZ's subprocessors?
LIFELENZ lists 4 subprocessors on its trust center, including Microsoft, Amazon Web Services, ADP, CookieYes. Buyers use this for fourth-party risk review.
Where does LIFELENZ host or store data?
LIFELENZ hosts on AWS, and handles Customer personally identifiable information, Employee personally identifiable information, Credit card information, Personal health information. Data residency details are on its trust center.
Where is LIFELENZ's trust center or security page?
LIFELENZ's trust center is at https://trust.lifelenz.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Do you have a Data Privacy Framework Certification? If so, why is it relevant?
Yes, LifeLenz has a Data Privacy Framework Certification. This certification demonstrates our commitment to protecting personal data and complying with global privacy standards. The Data Privacy Framework Certification is relevant because it ensures that we meet the rigorous requirements for handling and processing personal information securely and responsibly. Additionally, it is an approved data transfer mechanism, which means we can transfer personal data internationally without solely relying on Standard Contractual Clauses (SCCs). This flexibility helps us streamline data transfers while remaining compliant with privacy regulations. This certification is particularly important for: - International Compliance: It aligns with major global privacy regulations, which govern how personal data must be protected and managed. - Customer Trust: By adhering to a certified privacy framework, we reinforce trust with our customers, providing assurance that their data is handled with the highest standards of privacy and security. - Accountability: The certification process requires regular assessments and improvements, ensuring that we remain accountable and proactive in managing data privacy risks.
How have you built Privacy By Design into the product?
LifeLenz has integrated Privacy by Design into every aspect of our product to ensure data privacy and security from the ground up. Here’s how we incorporate Privacy by Design: - Privacy in Product Development: Privacy considerations are embedded in each stage of product development. Before any feature is designed or deployed, we assess its potential impact on user privacy and implement measures to minimize data collection and exposure. - Data Minimization: We only collect and retain the minimum amount of data necessary for functionality. Our systems are designed to avoid storing sensitive information unless absolutely required, reducing privacy risks and exposure. - User Control and Transparency: We empower users with control over their data. Clear privacy settings allow users to manage what data is collected, retained, and shared. Additionally, our privacy policies are transparent, giving users clear insights into how their data is used. - Access Controls and Encryption: We enforce strict access controls to ensure that only authorized personnel can access sensitive data. All data is encrypted both in transit and at rest, protecting it from unauthorized access and breaches. - Regular Privacy Impact Assessments (PIAs): We conduct ongoing PIAs to evaluate new features and processes for privacy risks. This proactive approach helps us identify and mitigate potential privacy issues before they arise. - Privacy Training and Culture: Privacy by Design is ingrained in our organizational culture. Our team is regularly trained on privacy principles, ensuring that everyone—from developers to customer support—prioritizes privacy in their work. - Proactive Compliance with Regulations: Our Privacy by Design approach ensures we meet and often exceed requirements from regulations like GDPR and CCPA. By integrating these principles, we are committed to maintaining high standards of privacy protection.
What information does LifeLenz provide to the Works Council in Germany, and how does LifeLenz collaborate with the Works Council to gain approval for using its software?
For LifeLenz, understanding what information is relevant to a German Works Council and collaborating effectively with the Works Council is essential to ensuring compliance and fostering a productive, transparent relationship. Here’s how LifeLenz addresses this: 1. Relevant Information for the Works Council: - Data Privacy and Employee Monitoring: - Data Collection and Usage Policies:Details on what employee-related data the software collects, processes, and retains, with specific focus on any tools used for monitoring or analytics. - Purpose and Scope of Data Collection: Explanation of why data is collected and how it will be utilized, especially if employee activities are being monitored or analyzed within the system. - Data Privacy Impact Assessments (DPIAs): Summaries of privacy impact assessments conducted to identify any potential risks to employee privacy from using LifeLenz software. - GDPR Compliance Measures: Assurance that LifeLenz meets GDPR requirements for transparency, consent, data minimization, and data protection, ensuring employee privacy. - Introduction of New Technology and Security Systems: - Technology Implementation and Usage Policies: Information about any technology, software, or security measures that may impact employees’ privacy or daily tasks (e.g., SSO, device compliance checks). - Zero Trust Security Strategy: Explanation of how the zero-trust approach works, including access controls that ensure employees’ data is only accessible based on roles and need. - Workplace Policies and Changes: - Remote Work and Security Policies: Policies and practices that ensure the security of employee data in remote environments, including any remote monitoring policies and their relevance to security. - Data Access and Transparency: Clear access controls for employee data within the software, showing who can access certain data and under what circumstances. - Employee Training and Awareness: Information on mandatory security and privacy training…
How do you comply with the GDPR?
LifeLenz is fully committed to GDPR compliance, especially in managing Data Subject Access Requests (DSARs) for our B2B customers. As a data processor, we operate in a way that supports our customers (the data controllers) in fulfilling their GDPR obligations while protecting personal data and respecting privacy rights. Here’s how we achieve this: 1. Controller-Managed DSAR Requests: - LifeLenz does not process DSARs directly from our customers' employees. Instead, since our B2B customers are the data controllers, they are responsible for managing DSARs on behalf of their employees. This approach aligns with GDPR’s designation of controllers and processors and ensures compliance with privacy obligations. 2. Support for Customer-Initiated Requests: - When a data controller (our customer) submits a DSAR to us on behalf of an employee, LifeLenz will fully facilitate and support the request. We promptly provide the necessary data to the customer to enable them to meet their GDPR obligations efficiently. 3. Data Minimization and Purpose Limitation: - We adhere to data minimization principles by only collecting and processing the data necessary for our services. Each data processing activity is limited to specific, legitimate purposes, ensuring GDPR compliance throughout our operations. 4. Privacy by Design and by Default: - LifeLenz integrates privacy into every stage of our product development, ensuring that data protection is foundational to our platform. This includes regular privacy impact assessments and security reviews to maintain robust privacy protections. 5. Data Security and Encryption: - We protect all personal data with strict security controls, including encryption for data both at rest and in transit. Our zero-trust security strategy enforces access control policies, allowing only authorized personnel access to sensitive data. 6. Data Transfers and Privacy Framework Certification: - LifeLenz complies with GDPR data transfer requirements and holds a Data…
Do you encrypt data at rest?
We utilize industry-standard encryption protocols to ensure that all sensitive data is protected while stored in our systems. This includes the use of AES-256 encryption, which meets compliance requirements for SOC 2, GDPR, and other data protection frameworks. Encrypting data at rest is a critical component of our security strategy, aligned with our commitment to zero-trust principles and privacy by design.
Do you support Single Sign-On (SSO)?
We offer SSO integration to streamline user access and enhance security by enabling centralized authentication. SSO is compatible with major identity providers, ensuring that users can securely access our platform using their existing credentials. This aligns with our zero-trust security strategy, reducing password fatigue and minimizing security risks associated with multiple logins.
How do you monitor for security breaches?
Our security monitoring approach includes: - Continuous Monitoring: We use advanced security tools to monitor network traffic, system events, and user activities 24/7, identifying unusual or potentially malicious behavior. - Threat Intelligence Integration: Our system integrates threat intelligence feeds to stay updated on emerging threats, allowing us to proactively adjust our defenses. - Real-Time Alerts and Incident Response: We have automated alerting systems that notify our security team of any suspicious activities or potential breaches. Our incident response team is trained to act quickly to investigate and mitigate threats. - Regular Audits and Vulnerability Assessments: In addition to real-time monitoring, we conduct regular security audits and vulnerability assessments to identify and address potential risks.
How do you enforce Zero Trust in the product?
We continuously enforce Zero Trust principles and practices into our product and organization through: - Identity Verification: Every user and device must be authenticated and authorized before accessing any resource. This includes enforcing Multi-Factor Authentication (MFA) to add an additional layer of security. - Least Privilege Access: Users are granted only the minimum access required to perform their tasks. Access controls are continuously reviewed and adjusted based on role and necessity. - Micro-Segmentation: We segment our network and application environments to restrict access and limit potential breach impact. Each segment is isolated, minimizing the spread of any potential threats. - Continuous Monitoring and Analytics: All access requests and activities are monitored in real-time. We utilize behavioral analytics to detect anomalies and potential threats, allowing us to take immediate action if needed. - Strict Device Compliance: Only trusted, compliant devices can access our resources. We enforce device health checks and regular security updates to prevent untrusted devices from entering our network.