SOC2C

CAOS AG security & compliance

An overview of CAOS AG's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 Type II · Listed
FrameworksISO 27001, SOC 2 Type II, GDPR, CCPA
Penetration testNot listed
Subprocessors3 listed
HostingGCP
Trust centerView

Security questions about CAOS AG

Is CAOS AG secure?
Security isn't a single yes/no, but CAOS AG is SOC 2 Type II compliant and holds ISO 27001, SOC 2 Type II, GDPR, CCPA. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does CAOS AG have a bug bounty or vulnerability disclosure program?
CAOS AG hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@zitadel.com or via a /security page (CAOS AG lists a security contact).
Who are CAOS AG's subprocessors?
CAOS AG lists 3 subprocessors on its trust center, including Google Cloud Platform, Postmark (AC PM LLC), Twillio Inc.. Buyers use this for fourth-party risk review.
Where does CAOS AG host or store data?
CAOS AG hosts on GCP, and handles Customer personally identifiable information, Employee personally identifiable information, Customer uploaded data. Data residency details are on its trust center.
Where is CAOS AG's trust center or security page?
CAOS AG's trust center is at https://trust.zitadel.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See CAOS AG's full SOC 2 profile →