SOC2C

Is this your company? Buyers are checking Smart Contract Solutions. Inc here. Claim openzeppelin.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Smart Contract Solutions. Inc logo

Smart Contract Solutions. Inc

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Smart Contract Solutions. Inc is SOC 2 Type II compliant. Smart Contract Solutions. Inc also holds GDPR, and CCPA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Founded in 2015, OpenZeppelin is the world leader in securing blockchain applications and smart contracts. Its bedrock open source Contract Libraries are a public good and industry standard for smart contract development. OpenZeppelin’s professional expertise, unified with the Defender developer security platform, integrates through clients’ development lifecycles, so teams can plan, code, audit, deploy and operate projects faster and more safely. OpenZeppelin has established its security program aligned with SOC 2 and ISO/IEC 27001 controls. The program is led by a team dedicated to Security

Compliance & infrastructure

Hosting
AWS
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

2

Subprocessors

19
  • A
    Amazon Web Services · aws
  • G
    GitHub · github
  • G
    Google Workspace · gsuiteadmin
  • S
    Slack · slack
  • C
    Checkr · customercheckr
  • C
    Cloudflare · cloudflare
  • H
    Hubspot · hubspot
  • K
    KnowBe4
  • L
    Linear
  • N
    Netlify · netlify
  • N
    Notion · notion
  • P
    PagerDuty
Show all 19 subprocessors
  • S
    Sentry
  • V
    Vanta
  • Z
    Zoom · zoom
  • A
    Anthropic · AI language model provider used for engineering assistance, research, and intern
  • O
    OpenAI · AI language model provider used for engineering, research, and internal producti
  • E
    Exafunction · Cloud compute infrastructure for AI workloads.
  • C
    Cursor · AI-assisted software development tool.

Compliance leadership

The person who leads Smart Contract Solutions. Inc's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Smart Contract Solutions. Inc's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Smart Contract Solutions. Inc SOC 2 compliant?
Smart Contract Solutions. Inc is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Smart Contract Solutions. Inc GDPR compliant?
According to Smart Contract Solutions. Inc's public trust center, Smart Contract Solutions. Inc is GDPR compliant. On SOC2C this listing is Listed.
Is Smart Contract Solutions. Inc CCPA compliant?
According to Smart Contract Solutions. Inc's public trust center, Smart Contract Solutions. Inc is CCPA compliant. On SOC2C this listing is Listed.
Is Smart Contract Solutions. Inc SOC 2 Type I or Type II?
Smart Contract Solutions. Inc is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Smart Contract Solutions. Inc's SOC 2 for a vendor risk assessment?
Yes. Smart Contract Solutions. Inc's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by Smart Contract Solutions. Inc

Reproduced from Smart Contract Solutions. Inc's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How does OpenZeppelin protect my information in Defender?
Defender has multiple security and data protection controls, including: - Role-based access control (RBAC): Privileged access is provided based on the person’s role, effectively adopting the need-to-know principle. - Multi-factor authentication (MFA): Enhances access control security and prevents system usage via compromised credentials. - Encryption in transit: Your data is secure with state-of-the-art encryption in transit via TLS 1.2 and 1.3. - Encryption at rest: Your data is also protected at rest with AES-256 encryption using Amazon’s Key Management Service (AWS KMS). - Code review and testing: All code changes are peer reviewed. Our Platform goes through rigorous unit and integration testing before releases. - Penetration test: Our Platform is analyzed for vulnerabilities through periodic penetration testing from specialized third-parties. - DDoS protection: Our Platform is protected against decentralized denial-of-service (DDoS) attacks. OpenZeppelin is a cloud-native organization that only utilizes secure partners who are ISO 27001 certified or SOC 2 audited to host our infrastructure and applications.
Why should I trust your Contracts library?
We enable the community to protect the open economy with our securely designed open source libraries and code through secure patterns and best practices. Our code is trusted by the biggest players in the industry to secure over $50 billion in total value locked. We perform code reviews on all changes, and we maintain a high level of automated test coverage along with use of fuzzing and formal verification. We leverage our Security Research team’s knowledge and expertise for periodic code audits. Every release candidate has a public review period, and ethical hackers are invited to collaborate in the security of our contracts by participating in our Bug Bounty Program through Immunefi. Check our Contracts Security Center for more information about the security or our Contracts library.
How secure is OpenZeppelin?
At OpenZeppelin, we practice the security controls we recommend to our customers and implement them in our products. That’s why we enforce identity and access management controls across our infrastructure assets and corporate systems, including Single Sign-On (SSO) with multi-factor authentication (MFA), role-based access control (RBAC), strong password policies, and a corporate password manager system, finding the delicate balance between knowledge sharing and the need-to-know principle. We invest heavily in personnel security with actions such as background checks before hiring following local regulations, Security training upon hiring and at least once a year, monthly Security Awareness Newsletters, continuous Phishing program and testing, amongst others. Our Head of Security reviews all suspected or confirmed security-related incidents. We contact affected customers using the most appropriate means. Please email [security@openzeppelin.com](mailto:security@openzeppelin.com) to report suspected security incidents. We analyze our partners’ risks before contracting and periodically thereafter to ensure they maintain the expected robust security posture.
How do you manage data privacy?
OpenZeppelin operates in accordance with major privacy acts and best practices to ensure your data is safe, protected and in adherence with current law. You own your data and have control over it. Please contact [legal@openzeppelin.com](mailto:legal@openzeppelin.com) if you have any questions about our Privacy Policy, the personal data we hold about you, or if you like to report an ethics or workplace issue.
How do I contact OpenZeppelin
Reach out about product security or company security please email [security@openzeppelin.com](mailto:security@openzeppelin.com). For questions about contracts, privacy, or to report an ethics or workplace issue please email [legal@openzeppelin.com](mailto:legal@openzeppelin.com). To report a vulnerability in our contracts library please consult our Bug Bounty Program.