SOC 2 Status.

An honest current-state page. We would rather tell you plainly that we are not certified than market a "ready" claim that is easy to misread.

Current status: not certified

GozAround is not SOC 2 certified, and we do not claim to be. What we can show you is the set of security controls we operate every day, and we are glad to support your vendor security review with documentation. If formal certification becomes part of our roadmap, we will say so here.

Controls we operate today (organized around the SOC 2 trust criteria)

  • Security: AES-256 encryption at rest, TLS 1.2+ in transit, bcrypt password hashing, rate-limiting on auth, CSRF on every form, multi-tenant isolation enforced query-by-query.
  • Availability: Cloudflare edge proxy, monitored uptime, and alerting on error rates.
  • Processing integrity: Full audit trail on every state-changing action via activity_log. Idempotent event handling on Stripe webhook + receipt capture pipelines. Defensive query patterns (prepared statements, schema-validated input).
  • Confidentiality: Role-based access enforced at every endpoint. Banking fields encrypted with HMAC-authenticated symmetric encryption. No PII flows to third-party browser SDKs (none embedded).
  • Privacy: GDPR/CCPA-aware data flows. DPA available. Right-to-delete + right-to-export supported. Subprocessors disclosed publicly on /trust/privacy.

What we can share for your security review

  • A written security overview of the controls above.
  • Our Data Processing Agreement (DPA) and subprocessor list.
  • Architecture notes and answers to your security questionnaire.

If your procurement asks about SOC 2

Tell them plainly: GozAround is not SOC 2 certified today. If that is a hard requirement, email security@gozaround.co and we will work through your security review with the control documentation we have.

Questions about security or compliance?