SOC2C

Is this your company? Buyers are checking Mergify here. Claim mergify.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Mergify logo

Mergify

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Mergify is SOC 2 Type II compliant. Mergify also holds GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Welcome to our comprehensive security and trust page, where we demonstrate our unwavering dedication to safeguarding your valuable data and maintaining the highest industry standards. At Mergify, we understand that trust is paramount in the world of SaaS software for developer tools. That's why we have implemented rigorous security measures, including continuous monitoring, thorough penetration testing, and compliance with SOC II standards. In this detailed overview, we provide transparency by sharing our compliance reports, offering insight into our security practices, and showcasing our comm

Compliance & infrastructure

Hosting
GCP
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

3

Subprocessors

6
  • C
    Cloudflare · Infrastructure
    101 Townsend St, San Francisco, CA 94107, United States
  • S
    Stripe · Payment service
    185 Berry St Ste 55 San Francisco, CA, 94107-5705, United States
  • D
    Datadog · Monitoring platform
    New York Times Bldg, 620 8th Ave 45th Floor, New York, NY 10018, United States
  • G
    Google Cloud Platform · Infrastructure
    1600 Amphitheatre Pkwy, Mountain View, CA 94043, United States
  • P
    Plain · Customer support tickets
    3rd Floor 1 Ashley Road, Altrincham, Cheshire, United Kingdom, WA14 2DT
  • S
    Sentry · Error tracking
    45 Fremont Street, 8th Floor, San Francisco, CA 94105, United States

Compliance leadership

The person who leads Mergify's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Mergify's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Mergify SOC 2 compliant?
Mergify is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Mergify GDPR compliant?
According to Mergify's public trust center, Mergify is GDPR compliant. On SOC2C this listing is Listed.
Is Mergify SOC 2 Type I or Type II?
Mergify is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Mergify's SOC 2 for a vendor risk assessment?
Yes. Mergify's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Mergify penetration tested?
Mergify hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Business & Industrial peers that completed SOC 2