SOC2C

Is this your company? Buyers are checking Sqldbm - Online Data Modeling Tool here. Claim sqldbm.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Sqldbm - Online Data Modeling Tool logo

Sqldbm - Online Data Modeling Tool

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Sqldbm - Online Data Modeling Tool is SOC 2 Type II compliant.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Headquatered in San Diego, California, SqlDBM is the most advanced, cloud-native, database modeling platform for enterprise cloud data management. Using powerful data source connectivity and design features, modelers can develop their entire database schema without writing a single line of code. SqlDBM supports leading cloud-based database providers like Snowflake, Databricks, Azure Synapse, and Amazon Redshift and many on-premise solutions like Postgres, MySQL and MS SQL Server. At SqlDBM, we prioritize the security and privacy of our customers above all else. We understand the importance of

Compliance & infrastructure

Hosting
AWS
Data handled
Customer personally identifiable informationCredit card informationPersonal health informationDatabase Metadata (DDL files)Data within customer databases

Documents

23

Subprocessors

1
  • A
    Amazon Web Services · Infrastructure hosting provider
    US West Region

Compliance leadership

The person who leads Sqldbm - Online Data Modeling Tool's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Sqldbm - Online Data Modeling Tool's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Other certifications
    List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Sqldbm - Online Data Modeling Tool SOC 2 compliant?
Sqldbm - Online Data Modeling Tool is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Sqldbm - Online Data Modeling Tool SOC 2 Type I or Type II?
Sqldbm - Online Data Modeling Tool is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Sqldbm - Online Data Modeling Tool's SOC 2 for a vendor risk assessment?
Yes. Sqldbm - Online Data Modeling Tool's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Sqldbm - Online Data Modeling Tool penetration tested?
Sqldbm - Online Data Modeling Tool hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Can I get Sqldbm - Online Data Modeling Tool's SOC 2 report?
Sqldbm - Online Data Modeling Tool's SOC 2 report is available on request. Request access through SOC2C and we coordinate the company-side NDA and delivery.

Answers published by Sqldbm - Online Data Modeling Tool

Reproduced from Sqldbm - Online Data Modeling Tool's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How do you ensure data is protected at all times?
SqlDBM doesn't need your data to work, rather, we only need metadata of your databases and we provide secure methods for you to provide this data to our platform. Additionally, we have security controls in place to protect data both in-transit and at-rest. All communications between our clients and our platform, as well as among components and services that support our platform is always encrypted with the latest TLS protocol. Customer data at-rest is stored in secured, non-public S3 bucket and is also encrypted with AES encryption.
How do you handle the data you collect?
The only data you need to provide to us to start using out platform is metadata of your database or data warehouse. This data can be provided via two main methods: - Manually generate a data definition language (DDL) file and upload it to our platform - For some data warehouse tools such as Snowflake, there is a direct connect option in which our platform can automatically generate and pull metadata from your data warehouse. Regardless of which option you choose to go with, we will never collect and store the actual data hosted in your database.
How is customer modeling data handled when subscription ends?
By default, our policy is to retain data indefinitely, and securely, for product improvement purposes. However, customers can submit written request when their subscription end to either have their models and metadata returned to them or permanently destroyed.
What security technologies are in place to protect your networks externally and internally?
All publicly accessible endpoints are protected with a web application firewall (WAF) and a DDoS protection solution. All networks are controlled strictly with access control lists (ACLs) and implicitly deny all traffic unless specifically allowed. Access to internal networks is protected with the following controls: - IP whitelist - VPN - MFA
Do you support Single Sign-On (SSO)?
Yes, we support SSO login integration with various well-known identity providers, including Microsoft, Google, Okta, SecureAuth, CyberArk, Github, and Asana.