SOC2C

Ozone API security & compliance

An overview of Ozone API's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 Type II · Listed
FrameworksISO 27001, SOC 2 Type II
Penetration testNot listed
Subprocessors13 listed
HostingAWS, Azure
Trust centerView

Security questions about Ozone API

Is Ozone API secure?
Security isn't a single yes/no, but Ozone API is SOC 2 Type II compliant and holds ISO 27001, SOC 2 Type II, and undergoes third-party penetration testing. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Ozone API have a bug bounty or vulnerability disclosure program?
Ozone API hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@ozoneapi.com or via a /security page (Ozone API lists a security contact).
Who are Ozone API's subprocessors?
Ozone API lists 13 subprocessors on its trust center, including Amazon Web Services, Microsoft Azure, MongoDB Atlas, Okta, Confluence. Buyers use this for fourth-party risk review.
Where does Ozone API host or store data?
Ozone API hosts on AWS, Azure. Data residency details are on its trust center.
Where is Ozone API's trust center or security page?
Ozone API's trust center is at https://trust.ozoneapi.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See Ozone API's full SOC 2 profile →