Skip to main content
SOC 2 Type II In Progress

Security & Trust Center

SaaS Factory is built for enterprises that have security review requirements. This page documents our security controls, compliance posture, sub-processor list, and how to access compliance documentation for procurement.

GDPR Compliant AES-256 Encryption DPA Available

Last updated: August 2026 · Questions? security@saas-factory.ai

SOC 2 Type II
Audit in progress
In Progress
GDPR / UK GDPR
DPA, data subject rights, and consent management built-in.
Needs attention

Security Controls

Built to pass your security review

Security is not a feature we bolt on. Every product built on SaaS Factory inherits these controls from the platform infrastructure from day one.

Encryption at Rest

AES-256-GCM encryption on all sensitive fields — GitHub tokens, API keys, PII. Neon Postgres volumes are encrypted at the storage layer.

Encryption in Transit

TLS 1.3 enforced on all connections. HSTS with 1-year max-age. Certificate pinning on mobile SDKs.

Access Control & RBAC

Role-based access on every API endpoint. Project-level ownership model. Row-Level Security (RLS) in Postgres prevents one customer's data leaking into another's.

Immutable Audit Log

Every state-changing operation is written to an append-only audit log with actor, timestamp, and resource ID. 2-year retention for SOC 2.

Vulnerability Management

Automated dependency scanning on every PR. OWASP Top-10 checklist validated by the security agent. CVE triage SLA: 24 h critical, 72 h high.

Vendor Security Review

All sub-processors have DPAs in place. Third-party access is reviewed quarterly. Anthropic, Vercel, Neon, Stripe, GitHub, Temporal Cloud and Resend hold SOC 2 reports.

Data Isolation

Customer data isolation via Postgres RLS. Enterprise customers get a dedicated database namespace. No co-mingling of production data between customers.

Backups & Recovery

Automated daily snapshots with 30-day retention. Point-in-time restore to any second in the last 24 hours. Tested recovery quarterly.

Security Incident Response

Documented IR plan with <1 h detection, <4 h containment targets. Affected customers notified within 72 h per GDPR Article 33.

Infrastructure Hardening

Vercel edge network with WAF, DDoS mitigation, and rate limiting. Neon Postgres isolated VPC. No direct internet access to database layer.

Uptime & Status

Every product built on SaaS Factory gets its own live status page.

SOC 2 Trust Service Criteria

All five trust categories covered

Our SOC 2 Type II audit covers the full AICPA Trust Service Criteria framework. Below are the criteria our controls are organised around. Measured status from our own continuous audits follows.

Common Criteria
9 controls
CC1Control Environment
CC2Communication & Information
CC3Risk Assessment
CC4Monitoring Activities
CC5Control Activities
CC6Logical & Physical Access Controls
CC7System Operations
CC8Change Management
CC9Risk Mitigation
Availability
3 controls
A1.1System Availability Monitoring
A1.2Incident & Outage Procedures
A1.3Backup & Recovery
Confidentiality
2 controls
C1.1Confidential Data Classification
C1.2Confidential Data Disposal
Processing Integrity
2 controls
PI1.1Data Validation & Accuracy
PI1.2Processing Completeness
Privacy
6 controls
P1.0Privacy Notice & Choice
P3.0Data Collection & Consent
P4.0Data Use & Retention
P5.0Data Subject Rights (GDPR)
P6.0Data Disclosure to 3rd Parties
P8.0Right to Erasure & Portability

Measured control status

From SaaS Factory's own continuous automated audits of this platform — not a third-party attestation.

FrameworkScorePassingPartialNeeds attentionAssessedStatus
SOC 296%12108 Jul 2026Partial
GDPR75%9038 Jul 2026Needs attention
ISO 2700191%10018 Jul 2026Needs attention
HIPAA100%10008 Jul 2026Operational

Sub-Processors

Our third-party data processors

All sub-processors hold DPAs with SaaS Factory and have been reviewed for SOC 2 or equivalent certification. We maintain this list and notify customers of changes with 30 days’ notice.

Anthropic

Purpose
AI model inference — pipeline agent reasoning
Region
USA
Certifications
SOC 2 Type II
DPA
In place

Vercel

Purpose
Application hosting, serverless runtime, CDN
Region
Global (USA primary)
Certifications
SOC 2 Type IIISO 27001
DPA
In place

Neon

Purpose
Postgres database hosting
Region
USA / EU
Certifications
SOC 2 Type II
DPA
In place

Stripe

Purpose
Payment processing, subscription billing
Region
USA / EU
Certifications
SOC 2 Type IIPCI DSS Level 1
DPA
In place

GitHub

Purpose
Source control, CI/CD, PR pipeline
Region
USA
Certifications
SOC 2 Type IIISO 27001
DPA
In place

Temporal Cloud

Purpose
Workflow orchestration, cron scheduling
Region
USA / EU
Certifications
SOC 2 Type II
DPA
In place

Resend

Purpose
Transactional email delivery
Region
USA
Certifications
SOC 2 Type II
DPA
In place

To be notified of sub-processor changes, email security@saas-factory.ai and ask to join our sub-processor change notification list.

Compliance Documents

Documentation for your procurement team

The documents below are typically required during enterprise security reviews. Reach out to get started — we aim to turn a request around within 1 business day.

Available to all customers

Data Processing Agreement (DPA)

Standard DPA based on the EU Standard Contractual Clauses (SCCs). Covers GDPR Article 28 controller–processor obligations. Pre-signed version available for download.

Enterprise — request via sales

Business Associate Agreement (BAA)

HIPAA Business Associate Agreement available for Enterprise customers operating in healthcare verticals. Contact our compliance team to execute.

Available on request

Security Questionnaire (CAIQ / SIG Lite)

Pre-filled CSA CAIQ and SIG Lite questionnaires for security review programmes. Last updated August 2026.

Publicly available

Privacy Policy

GDPR-compliant privacy policy covering data collection, processing, retention, sub-processors, and data subject rights.

Data Residency

Your data stays where regulations require

Choose your database region at project creation. Data at rest never leaves your selected region. Backups are stored in the same region.

US (Virginia)
US (Oregon)
UK (London)
EU (Frankfurt)
Singapore
Brazil (São Paulo)

UK hosting is governed by UK GDPR. For EU personal data with a strict EU-residency requirement, choose Frankfurt — UK transfers rely on the UK adequacy decision rather than being inside the EEA.

Additional regions available on Enterprise plans. Contact sales@saas-factory.ai for dedicated infrastructure.

Responsible Disclosure

Security vulnerability reporting

We take security reports seriously. If you discover a vulnerability, please report it responsibly and we will work with you to address it quickly.

Response SLA
We acknowledge all reports within 24 hours and provide triage within 72 hours.
Safe harbour
We will not pursue legal action against researchers who follow responsible disclosure and do not access or exfiltrate customer data.

Ready to complete your security review?

Our security team is ready to answer questionnaires, provide compliance documentation, and execute DPAs and BAAs for Enterprise procurement. Typical turnaround: 1 business day.