SOC2C

Is this your company? Buyers are checking Vecflow here. Claim vecflow.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Vecflow logo

Vecflow

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Vecflow is SOC 2 Type II compliant. Vecflow also holds ISO 27001.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Welcome to the VecFlow Security Portal! This portal provides an overview of our commitment to security and compliance. You can find our certifications, security practices, and explore details on our controls.

Compliance & infrastructure

Compliance leadership

The person who leads Vecflow's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Vecflow's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

4/11 details · 36%

SOC2C shows the verified essentials. 7 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Subprocessors
    List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Vecflow SOC 2 compliant?
Vecflow is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Vecflow ISO 27001 certified?
According to Vecflow's public trust center, Vecflow is ISO 27001 certified. On SOC2C this listing is Listed.
Is Vecflow SOC 2 Type I or Type II?
Vecflow is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Vecflow's SOC 2 for a vendor risk assessment?
Yes. Vecflow's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Vecflow penetration tested?
Vecflow hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by Vecflow

Reproduced from Vecflow's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How does August approach security?
August's security approach is comprehensive, focusing on both preventive measures and swift incident response. We enforce strict internal authentication and access control using unique user identifiers and hardware-backed FIDO2 multi-factor authentication for all personnel. Employee devices are centrally managed to adhere to our security policies, with data redundantly backed up across multiple data centers, primarily in the United States, unless otherwise specified by the client. August's secure development lifecycle incorporates industry best practices, including rigorous code reviews, static and dynamic application security testing. Our infrastructure is protected through network segmentation, firewalls, and Web Application Firewalls (WAFs), ensuring unauthorized access is prevented. Continuous security monitoring and intrusion detection systems are in place to identify and mitigate potential threats. In case of a security incident, August follows established incident response policies and regularly tested playbooks. Additionally, we conduct regular third-party offensive security assessments to evaluate and strengthen our security posture comprehensively.
Which information does August have available to accelerate the IT Security/Risk Review process?
Under a Non-Disclosure Agreement (NDA), August can provide our "Security Welcome Packet," which includes detailed information on our security practices. We are also prepared to share our SOC 2 Type 2 report, along with industry-standard questionnaires such as VSA-Full, SIG Lite, and CAIQv4, to expedite the Security/Risk review process.
How do you authenticate customers?
August leverages Single Sign-On (SSO) with SAML for customer authentication. This allows firm administrators to centrally manage access to August and enforce security policies effectively. Users can seamlessly log in using their firm’s credentials, eliminating the need for an additional password.
Where are your servers located?
August operates on Cloud providers, with all data processing and storage primarily occurring in the United States. We also offer support for data storage in other regions upon request to accommodate client needs.
Can I request data deletion or export?
Yes, August provides customers with the ability to request data deletion or export. We offer secure and compliant methods for data export, allowing you to retrieve your data in a commonly used format. For data deletion, we ensure that all data is permanently removed from our systems in accordance with industry best practices.