SOC2C

Is this your company? Buyers are checking Vurvey here. Claim vurvey.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Vurvey logo

Vurvey

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Vurvey is SOC 2 Type II compliant.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Welcome to the Vurvey Labs Trust Center. This page acts as an overview to demonstrate our commitment to compliance and security. Here you can find our certifications, request documentation, and view high level details on controls we adhere to. To access sensitive documents within this portal, please click the lock icon next to the document and provide the requested information.

Compliance & infrastructure

Hosting
GCP
Data handled
Customer personally identifiable informationCredit card informationPersonal health information

Documents

9

Subprocessors

15
  • G
    Google Cloud Platform · Cloud infrastructure
    United States
  • C
    Cloudflare · Cloud infrastructure
    United States
  • B
    Brightcove (Zencoder) · Video Encoding
    United States
  • S
    Sendgrid · Communication
    United States
  • I
    Intercom · Customer support
    United States
  • A
    Anthropic · AI
    United States
  • G
    Google Workspace · Identity provider
    United States
  • V
    Vonage · Video recording
    United States
  • O
    OpenAI · AI
    United States
  • S
    Stability AI · AI
    United States
  • L
    LogRocket · Customer support
    United States
  • E
    ElevenLabs · Engineering
    United States
Show all 15 subprocessors
  • G
    GitHub · Version control
    United States
  • J
    Jira · Collaboration
    United States
  • V
    Vanta · Security
    United States

Compliance leadership

The person who leads Vurvey's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Vurvey's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Other certifications
    List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Vurvey SOC 2 compliant?
Vurvey is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Vurvey SOC 2 Type I or Type II?
Vurvey is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Vurvey's SOC 2 for a vendor risk assessment?
Yes. Vurvey's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Vurvey penetration tested?
Vurvey hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Can I get Vurvey's SOC 2 report?
Vurvey's SOC 2 report is available on request. Request access through SOC2C and we coordinate the company-side NDA and delivery.

Answers published by Vurvey

Reproduced from Vurvey's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How does Vurvey define Personally Identifiable Information (PII)?
At Vurvey, we define Personally Identifiable Information as information that can uniquely identify an end user or a combination of information that could reasonably identify a single end user. Vurvey may process the following information: (1) email, first and last name; (2) Demographic including ethnicity, gender and age; (3) IP Address
Describe the application architecture and the protections in place to protect the data
Vurvey is a SaaS platform for collecting survey responses from end consumers and viewing the responses. The application is accessed via secure login from a web browser located at a secure URL (vurvey.app). The Vurvey platform utilizes Google Cloud Platform (GCP) to store and process customer data. All data processing activities include data encryption for in-transit using Transport Layer Security (TLS/HTTPS) and at rest using the AES-256 algorithm.
What measures has Vurvey taken to minimize risk?
Vurvey has implemented a Privacy by Design model where there is minimal handling and storage of PII built into our product design. We continually refine the concepts of redaction, reduction, and transparency as our technology evolves.
AI (Artificial Intelligence) And Your Data
Your data is never used to train AI models. Vurvey's Responsible AI principles include: - We use caution with confidential customer information in AI tools, avoiding submission of sensitive data unless a) explicitly authorized and/or b) we have platform assurances that such data will not be used for training publicly available Large Language Models (LLMs.) - We do not fine-tune large language models. Fine-tuning alters the parameters and weights of an existing model by supplying labeled data. This has the potential to weaken built-in safety measures as well as leak sensitive data. - We anonymize all users by generating pseudo-identifiers. Personally identifiable information for users is never shared with the large language model. - We rigorously test and validate underlying algorithms that service AI models to identify and address potential issues before deployment. - We commit to complying with all customer agreements, policies, and directives in our AI deployments to the best of our ability and within the constraints of our systems and processes.

Business & Industrial peers that completed SOC 2