SOC2C

Is this your company? Buyers are checking Veracross LLC here. Claim veracross.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Veracross LLC logo

Veracross LLC

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Veracross LLC is SOC 2 Type II compliant. Veracross LLC also holds PCI DSS, GDPR, CCPA, and HIPAA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Trust Veracross with your security and privacy. Our Trust Center connects you to our privacy, security, and compliance programs, so you have all of the information you need to manage your data. Want access to our AI-enabled Trust Center? Request access now ↗️ [Website Privacy Policy](https://www.veracross.com/website-privacy-policy/) [Product Privacy Policy](https://www.veracross.com/veracross-product-privacy-policy/) [DSAR](https://privacy.saymine.io/veracross?type=donotsell) [Customer Data Processing Agreement (DPA)](https://vcwebdistro.blob.core.windows.net/web/All%20Portfolios/DPA/Data%20P

Compliance & infrastructure

Hosting
AWSAzure

Documents

1

Subprocessors

50
  • A
    Amazon Web Services · IaaS, hosting, databases, files storage, CDN
    United States, Germany, Australia
  • M
    Microsoft Azure · IaaS, database storage, identity management, SIEM
    United States, the Netherlands, Australia
  • S
    Salesforce · Customer account management
    United States
  • A
    Atlassian · Support tickets & documentation
    United States
  • V
    Vanta · Continuous security and compliance monitoring
    United States
  • D
    DocuSign · Document Management
    United States
  • A
    Accusoft Prizmdoc · File annotation
    United States
  • A
    Alert Logic · FIM, IDS, vulnerability scanning & alerting, SOC
    United States
  • B
    Bluesnap · Financial transaction processing
    United States
  • C
    Chili Piper · Customer support
    United States
  • G
    Google Ad Manager · Ad delivery & management
    United States
  • G
    Google Analytics · Analytics tracking
    United States
Show all 50 subprocessors
  • G
    Groove · Sales engagements & workflows
    United States
  • H
    Hootsuite · Marketing management
    United States
  • M
    Microsoft 365 · Email processing & delivery, file storage
    United States
  • P
    Pardot · Customer relationship management
    United States
  • P
    Pendo · Marketing communication & forms
    United States
  • S
    Simple Survey · Survey management
    United States
  • S
    SurveyMonkey · Survey management
    United States
  • W
    Wistia · Video registration
    United States
  • W
    WordPress · Landing & product pages
    United States
  • Z
    Zoom · Video calls, conferences, webinars
    United States
  • S
    StoredTech · Managed Service Provider
    United States, Australia
  • W
    Workable · Recruiting, candidate management
    Unites States
  • V
    Verified First · Candidate background checks
    Unites States
  • S
    Slack · Business communications
    United States
  • O
    Own Backup · Business systems backups
    United States
  • M
    MineOS · Vendor & privacy management
    United States, Israel
  • M
    Mimecast · Email security
    United States
  • B
    Bing Ads · Ad delivery & management
    United States
  • A
    Articulate · Marketing operations
    United States
  • E
    Enclave · Technical services
    Vietnam
  • E
    Encora · Technical services
    Global
  • S
    Support Ninja · Support services
    Global
  • T
    Twilio · SMS delivery
    Global
  • S
    Service Objects · Address & email validation
    United States
  • S
    Stripe · Financial transaction processing
    Global
  • R
    Rollbar · Logging & error reporting
    United States
  • S
    SpendHound · Vendor contract management
    United States
  • R
    Rackspace · Cloud file storage
    United States
  • M
    Mailgun · Email processing & delivery
    United States
  • L
    Litmos · Learning & training management
    United States
  • G
    Google Maps (API) · Address verification
    United States
  • G
    Google reCaptcha · Bot detection
    United States
  • D
    Datadog · Logging, SIEM
    United States
  • C
    Cloudinary · Cloud file storage
    United States
  • C
    Citrix ShareFile · File sharing services
    United States, Australia
  • R
    Recorded Future · Security Operations
    United States
  • R
    Responsive · RFP Management
    United States
  • 1
    1Password · Password Management
    United States

Compliance leadership

The person who leads Veracross LLC's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Veracross LLC's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Veracross LLC SOC 2 compliant?
Veracross LLC is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Veracross LLC PCI DSS compliant?
According to Veracross LLC's public trust center, Veracross LLC is PCI DSS compliant. On SOC2C this listing is Listed.
Is Veracross LLC GDPR compliant?
According to Veracross LLC's public trust center, Veracross LLC is GDPR compliant. On SOC2C this listing is Listed.
Is Veracross LLC CCPA compliant?
According to Veracross LLC's public trust center, Veracross LLC is CCPA compliant. On SOC2C this listing is Listed.
Is Veracross LLC HIPAA compliant?
According to Veracross LLC's public trust center, Veracross LLC is HIPAA compliant. On SOC2C this listing is Listed.

Answers published by Veracross LLC

Reproduced from Veracross LLC's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How does Veracross protect itself from bad actors on the dark web?
Veracross employs advanced monitoring of the dark web using a tool called Recorded Future which automatically scans and collects data from dark web sources. This information is used to identify potential threats, such as leaked credentials or sensitive company information. When compromised credentials are detected, these high priority alerts are automatically routed to our internal IT team who then take the necessary steps to mitigate the risk. With the ability of Recorded Future to proactively detect potential threats, it allows us to take preventative measures like password resets or account lockouts before a bad actor can utilize these credentials in a malicious manner. By staying vigilant and proactive, Veracross is actively mitigating the risk of unauthorized access and potential data breaches, ensuring a higher level of security.
Where is customer data stored?
Veracross maintains datacenters in the US, Germany, Australia, and the Netherlands. In most cases, Veracross stores customer data in the geography closest to the customer.
How does Veracross protect your data?
Veracross takes data privacy & security seriously. You can read our support article here, outlining our commitments to our community. You can also look at the Controls we maintain and check out other FAQs.
What is Veracross' backup & retention policy?
Veracross has comprehensive backup and retention policies to ensure the security and availability of customer data. Veracross continuously backs up customer data in multiple redundant locations, with daily backups available for a rolling 30-day window and monthly backups available for one year. These backups are stored at both AWS and Azure, ensuring data is encrypted and secure. Veracross has procedures in place to guide the secure retention and disposal of both company and customer data. These procedures ensure that data is retained and disposed of according to compliance and regulatory requirements. For our services, Veracross does not own customer data, therefore data retention is controlled by our customers. Should a customer leave Veracross, we will provide the customer with their data in a portable format within 30 days of termination and then delete their data. All departing customer data will be automatically deleted from our backups within 90 days. Veracross maintains a disaster recovery plan that includes the ability to recreate infrastructure in a different cloud region, maintaining a Recovery Point Objective (RPO) of 15 minutes or less and a Recovery Time Objective (RTO) of 4 hours or less. This plan ensures that Veracross can respond and recover promptly in the event of a disaster.
Does Veracross encrypt data?
Customer data is protected by TLS 1.2+ encryption when in-flight and AES-256 encryption when at rest.

Business & Industrial peers that completed SOC 2