SOC 2 Type II In Progress

Security & Trust Center

SaaS Factory is built for enterprises that have security review requirements. This page documents our security controls, compliance posture, sub-processor list, and how to access compliance documentation for procurement.

SOC 2 Type II GDPR Compliant AES-256 Encryption 99.9% SLA DPA Available

Last updated: June 2025 · Questions? security@saasfactory.ai

SOC 2 Type II
Audit in progress — report available to Enterprise customers under NDA
In Progress
GDPR / UK GDPR
Full GDPR compliance. DPA, data subject rights, and consent management built-in.
Operational
Pen Test
Annual third-party penetration test. Executive summary available under NDA.
Operational

Security Controls

Built to pass your security review

Security is not a feature we bolt on. Every product built on SaaS Factory inherits these controls from the platform infrastructure from day one.

Encryption at Rest

AES-256-GCM encryption on all sensitive fields — GitHub tokens, API keys, PII. Neon Postgres volumes are encrypted at the storage layer.

Encryption in Transit

TLS 1.3 enforced on all connections. HSTS with 1-year max-age. Certificate pinning on mobile SDKs.

Access Control & RBAC

Role-based access on every API endpoint. Project-level ownership model. Row-Level Security (RLS) in Postgres prevents cross-tenant data leaks.

Immutable Audit Log

Every state-changing operation is written to an append-only audit log with actor, timestamp, and resource ID. 2-year retention for SOC 2.

Vulnerability Management

Automated dependency scanning on every PR. OWASP Top-10 checklist validated by the security agent. CVE triage SLA: 24 h critical, 72 h high.

Vendor Security Review

All sub-processors have DPAs in place. Third-party access is reviewed quarterly. Anthropic, Vercel, Neon, Stripe, and GitHub all hold SOC 2 reports.

Data Isolation

Multi-tenant isolation via Postgres RLS. Enterprise customers get a dedicated database namespace. No co-mingling of production data across tenants.

Backups & Recovery

Automated daily snapshots with 30-day retention. Point-in-time restore to any second in the last 24 hours. Tested recovery quarterly.

Security Incident Response

Documented IR plan with <1 h detection, <4 h containment targets. Affected customers notified within 72 h per GDPR Article 33.

Infrastructure Hardening

Vercel edge network with WAF, DDoS mitigation, and rate limiting. Neon Postgres isolated VPC. No direct internet access to database layer.

Uptime & SLA

99.9% uptime SLA for Enterprise customers. Real-time status at status.saasfactory.ai. Historical incident archive published.

Penetration Testing

Annual third-party penetration test. Internal red-team exercises on every major release. Reports available to Enterprise customers under NDA.

SOC 2 Trust Service Criteria

All five trust categories covered

Our SOC 2 Type II audit covers the full AICPA Trust Service Criteria framework. Below is the current control status across all five categories.

Common Criteria
9 controls
Operational
CC1Control Environment
CC2Communication & Information
CC3Risk Assessment
CC4Monitoring Activities
CC5Control Activities
CC6Logical & Physical Access Controls
CC7System Operations
CC8Change Management
CC9Risk Mitigation
Availability
3 controls
Operational
A1.1System Availability Monitoring
A1.2Incident & Outage Procedures
A1.3Backup & Recovery
Confidentiality
2 controls
Operational
C1.1Confidential Data Classification
C1.2Confidential Data Disposal
Processing Integrity
2 controls
Operational
PI1.1Data Validation & Accuracy
PI1.2Processing Completeness
Privacy
6 controls
Operational
P1.0Privacy Notice & Choice
P3.0Data Collection & Consent
P4.0Data Use & Retention
P5.0Data Subject Rights (GDPR)
P6.0Data Disclosure to 3rd Parties
P8.0Right to Erasure & Portability

Sub-Processors

Our third-party data processors

All sub-processors hold DPAs with SaaS Factory and have been reviewed for SOC 2 or equivalent certification. We maintain this list and notify customers of changes with 30 days’ notice.

ProcessorPurposeDPA
AnthropicAI model inference — pipeline agent reasoning
VercelApplication hosting, serverless runtime, CDN
NeonPostgres database hosting
StripePayment processing, subscription billing
GitHubSource control, CI/CD, PR pipeline
InngestBackground job orchestration, cron scheduling
ResendTransactional email delivery

To be notified of sub-processor changes, email security@saasfactory.ai and ask to join our sub-processor change notification list.

Compliance Documents

Documentation for your procurement team

The documents below are typically required during enterprise security reviews. Reach out to get started — we aim to turn around NDA-gated documents within 1 business day.

Enterprise — request via sales

SOC 2 Type II Report

Full audit report available to Enterprise customers and prospects under NDA. Covers the Common Criteria (Security), Availability, Confidentiality, Processing Integrity, and Privacy trust service categories.

Available to all customers

Data Processing Agreement (DPA)

Standard DPA based on the EU Standard Contractual Clauses (SCCs). Covers GDPR Article 28 controller–processor obligations. Pre-signed version available for download.

Enterprise — request via sales

Business Associate Agreement (BAA)

HIPAA Business Associate Agreement available for Enterprise customers operating in healthcare verticals. Contact our compliance team to execute.

Enterprise — request under NDA

Penetration Test Summary

Annual third-party penetration test executive summary. Covers web application, API, and infrastructure layers. Full report available under NDA.

Available on request

Security Questionnaire (CAIQ / SIG Lite)

Pre-filled CSA CAIQ and SIG Lite questionnaires for security review programmes. Last updated 2025.

Publicly available

Privacy Policy

GDPR-compliant privacy policy covering data collection, processing, retention, sub-processors, and data subject rights.

Data Residency

Your data stays where regulations require

Choose your database region at project creation. Data at rest never leaves your selected region. Backups are stored in the same region.

🇺🇸 US East (Virginia)
🇺🇸 US West (Oregon)
🇬🇧 EU West (London)
🇩🇪 EU Central (Frankfurt)
🇸🇬 Asia Pacific (Singapore)
🇧🇷 South America (São Paulo)

Additional regions available on Enterprise plans. Contact sales@saasfactory.ai for dedicated infrastructure.

Responsible Disclosure

Security vulnerability reporting

We take security reports seriously. If you discover a vulnerability, please report it responsibly and we will work with you to address it quickly.

Response SLA
We acknowledge all reports within 24 hours and provide triage within 72 hours.
Safe harbour
We will not pursue legal action against researchers who follow responsible disclosure and do not access or exfiltrate customer data.

Ready to complete your security review?

Our security team is ready to answer questionnaires, provide compliance documentation, and execute DPAs and BAAs for Enterprise procurement. Typical turnaround: 1 business day.