Skip to content
Security & Trust / Compliance Dossier

Engineered to pass your security review on the first pass.

Soldius is independently audited to SOC 2 Type II and ISO 27001, with HIPAA-ready infrastructure deployed across 38 countries and a 99.98% uptime SLA. This page is the dossier your security team would otherwise request during procurement — laid out so it can be reviewed, exported, and signed off without a back-and-forth.

Founded
2021 · San Francisco
Certifications
SOC 2 Type II · ISO 27001
Last audit
March 2025
Coverage
38 countries
§ 01 — Certifications

Three audited certifications. Plain-language commitments you can hand to Legal.

The alphabet soup — SOC 2, ISO 27001, HIPAA — collapses into a single promise: your call audio, transcripts, and CRM-mirrored data are handled by infrastructure that has been independently audited against the controls a CISO already trusts. Soldius holds SOC 2 Type II (not Type III) and ISO 27001:2022; HIPAA-ready infrastructure is available under a signed Business Associate Agreement; GDPR and CCPA alignment is documented in our Data Processing Addendum. Audit reports, penetration-test summaries, and the latest SOC 2 bridge letter are exportable on request under NDA.

Reports are refreshed annually and updated through a continuous-monitoring program. The most recent SOC 2 observation window closed March 2025.

§ 02 — Compliance Register

Current certifications and operational posture.

A scannable register of every audited framework Soldius maintains, the scope of coverage, the auditor, and the date the most recent report was issued. Copy any row straight into your vendor questionnaire.

FRAMEWORK ACTIVE

SOC 2 Type II

Scope: Security, Availability, Confidentiality. Covers the Soldius production platform, supporting infrastructure, and the personnel operating it.

Auditor
Schellman & Co., LLC
Observation window
Apr 2024 — Mar 2025
Report issued
April 2025
Type
Type II (not Type III)
Request the report under NDA →
FRAMEWORK CERTIFIED

ISO/IEC 27001:2022

Scope: Information Security Management System (ISMS) covering product engineering, ML pipeline, customer data handling, and corporate IT.

Certifier
BSI Assurance UK Ltd.
Certificate No.
IS 781204
Issued
February 2025
Valid through
February 2028
Request the certificate →
FRAMEWORK READY

HIPAA-Ready Infrastructure

Scope: Encrypted storage of protected health information (PHI), BAA-eligible tenants, audited access controls, and signed Business Associate Agreements.

Standard
HIPAA Security Rule
Deployment
US-East & US-West regions
BAA
Available on request
Last attestation
Q1 2025
Request a BAA →
FRAMEWORK ALIGNED

GDPR · CCPA · UK GDPR

Scope: Lawful basis, data-subject rights, sub-processor disclosure, breach notification within 72 hours, and Standard Contractual Clauses for cross-border transfers.

DPA
Standard, SCCs included
Data residency
US · EU · APAC
Sub-processors
Listed publicly
Request the DPA →
OPERATIONAL SLA

99.98% uptime — backed by a public status page.

Measured monthly against the trailing 12-month window. Historical performance and live incident history are publicly visible at status.soldius.com. Service credits are issued automatically for any month falling below the committed SLA.

DATA-RESIDENCY-SELECTOR v3.2
  • United States us-east · us-west

    Primary processing region for North-American customers. Backed by AWS US-East-1 with cross-region failover to US-West-2.

    AES-256 at rest TLS 1.3 in transit
  • European Union eu-central · eu-west

    Frankfurt and Dublin regions. SCCs and UK addendum pre-signed; no data leaves the EU boundary for processing.

    AES-256 at rest TLS 1.3 in transit
  • Asia-Pacific ap-southeast · ap-northeast

    Singapore and Tokyo regions. Local processing for APAC customers under local data-protection regimes.

    AES-256 at rest TLS 1.3 in transit
§ 03 — Data Residency

Your conversations stay in the region you choose.

Call audio, transcripts, and CRM-mirrored records are processed and stored in the region selected at tenant creation. Soldius currently operates across 38 countries with regional processing available in the United States, the European Union, and Asia-Pacific.

ENCRYPTION · AT REST AES-256

All customer data — audio, transcripts, embeddings, CRM mirrors — encrypted with AES-256 using envelope encryption and customer-scoped KMS keys.

ENCRYPTION · IN TRANSIT TLS 1.3

All client-to-server and inter-service traffic uses TLS 1.3 with modern cipher suites. HSTS preload enabled on every Soldius domain.

KEY MANAGEMENT BYOK / HYOK

Bring-your-own-key or hold-your-own-key options available for Enterprise tier through AWS KMS and HashiCorp Vault integrations.

RETENTION Configurable

Default 24 months, configurable down to 30 days. Customer-initiated purge within 30 days of contract termination.

§ 04 — Security Controls

Technical and organizational controls behind the certifications.

A condensed map of the access, identity, and operational controls Soldius maintains — each paired with the artifact a security architect can request during review.

  1. 01

    Identity, SSO, and SCIM provisioning

    Audit artifact: SAML metadata XML · SCIM endpoint URL

    SAML 2.0 single sign-on with Okta, Azure AD, Google Workspace, Ping, JumpCloud, and any IdP that exposes a SAML metadata URL. SCIM 2.0 provisioning syncs users and groups in real time; de-provisioning is enforced within 60 seconds of an HR-system event.

  2. 02

    Role-based access control

    Audit artifact: RBAC matrix · Permission catalog

    Five default roles (Owner, Admin, Manager, Rep, Viewer) with field-level permissions on transcript visibility, PII redaction overrides, and CRM-write scopes. Custom roles available on Enterprise tier.

  3. 03

    Audit logs and forensic trails

    Audit artifact: Sample log export · SIEM integration guide

    Every read, write, export, and admin action is captured in an immutable audit log retained for 13 months. Streams to Splunk, Datadog, Panther, or any S3-compatible bucket via Kinesis Firehose.

  4. 04

    Penetration testing & vulnerability management

    Audit artifact: Annual pentest summary · SOC 2 carve-out

    Annual third-party penetration test by a CREST-accredited firm, plus quarterly internal red-team exercises. Critical findings resolved within 7 days; high-severity within 30 days. Bug-bounty program live on HackerOne.

  5. 05

    Personnel security & training

    Audit artifact: Training completion report · Background-check policy

    Background checks on every employee and contractor. Mandatory security and privacy training on hire and quarterly thereafter. Annual SOC 2 + ISO 27001 refresher attestations.

  6. 06

    Incident response & breach notification

    Audit artifact: IR runbook · Sample breach-notification template

    24/7 incident response on-call rotation. Customer notification within 72 hours of a confirmed breach — sooner when required by GDPR, CCPA, or contractual commitments. Post-mortems published for material incidents.

§ 05 — By the Numbers

The operational credibility a RevOps buyer asks about first.

99.98%
Uptime SLA
Trailing 12-month commitment, measured monthly, with public incident history.
38
Countries deployed
Live production tenants across the Americas, EMEA, and APAC — no inflated count.
14.2M
Conversations processed (2024)
A 312% year-over-year increase, processed on audited infrastructure.
<800ms
Call-to-CRM sync latency
6x faster than the conversation-intelligence category median.