Privacy Policy

Last updated: 1 October 2026

Overview

SOX&AUDIT ("we," "us," or "Company") provides an AI-powered audit automation platform to enterprise customers ("Customer," "you"). This Privacy Policy describes how we collect, process, and protect data in connection with our Services.

This policy applies to Customer organizations and their authorized users. Individual data processing terms are governed by your organization's policies and your agreement with SOX&AUDIT. This policy also describes the analytics used on our website, soxaudit.ai.

Data Categories

Customer Data

Data uploaded or created by Customer within the platform, including:

  • Audit evidence and supporting documentation
  • Control definitions and test procedures
  • Workpapers and audit findings
  • Internal communications within the platform

Customer owns all Customer Data. We process Customer Data solely to provide the Services as directed by Customer.

Account Data

Information about Customer's organization and authorized users:

  • Organization name, billing address, and contact information
  • User names, email addresses, and role assignments
  • Sign-in credentials, managed by our authentication provider, Auth0 (email and password, or Google or Microsoft sign-in)

Usage Data

Our website, soxaudit.ai, uses Google Analytics (Google LLC) and the Apollo.io website visitor tracker to collect information about visits to the website. The application at app.soxaudit.ai carries no third-party analytics.

AI Processing & Responsible AI

Our platform uses artificial intelligence to analyze documents, generate test procedures, and assist with audit workflows.

How AI Processes Your Data

  • AI models analyze Customer Data to extract information, classify documents, and generate outputs
  • AI processing uses the providers listed under Sub-processors below
  • AI outputs are tools to assist qualified professionals, not substitutes for professional judgment

AI Sub-processors

Our AI model providers are OpenAI and OpenRouter. Our document classification provider is TypeSafe.

Data Retention

We retain data according to the following principles:

  • Customer Data: Retained for the duration of the subscription
  • Audit Logs: Audit log retention is part of our enterprise readiness roadmap
  • Account Data: Retained while the account is active and for a reasonable period thereafter for legal and business purposes
  • Backups: Database backups run nightly to separate storage. Backup retention terms are being formalized as part of our enterprise readiness

Data Deletion

Customer data export and deletion processes are part of our enterprise readiness roadmap.

Data Security

The security measures in place today, and the items on our enterprise readiness roadmap:

  • Encryption: Connections use HTTPS (TLS), and the application and API send HSTS
  • Access Controls: Access is limited by role, and each customer's data is kept apart by tenant. Sign-up is by invitation only
  • Enterprise Identity: Single sign-on (SSO) and multi-factor sign-in are available for enterprise deployments
  • Monitoring: Security monitoring and alerting are being expanded as part of our enterprise readiness
  • Testing: Independent penetration testing is on our roadmap

Deployment Options

Enterprise deployment options, including dedicated cloud deployment (for example Microsoft Azure), are available for enterprise customers.

Sub-processors

We use the following sub-processors:

  • Cloud infrastructure: Hetzner Online GmbH
  • File storage: Microsoft Azure (Microsoft Corporation)
  • Authentication: Okta, Inc. (Auth0)
  • AI model providers: OpenAI, OpenRouter
  • Document classification: TypeSafe
  • Business email: Google Workspace (Google LLC)
  • Website hosting: Vercel Inc.
  • Website analytics: Google Analytics (Google LLC), Apollo.io

Customer Rights & Controls

Customers have the following rights regarding their data:

  • Correction: Modify or correct data within the platform
  • Export and Deletion: Customer data export and deletion processes are part of our enterprise readiness roadmap

Individual users within Customer organizations should direct privacy requests through their organization's designated administrator or privacy officer.

Compliance

Our controls are being built toward the SOC 2 Trust Services Criteria; a formal SOC 2 audit is on our roadmap.

Changes to This Policy

We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated to Customers via email or platform notification at least 30 days before taking effect. Continued use of the Services after changes become effective constitutes acceptance.

Contact

For privacy-related inquiries:

SOX&AUDIT Privacy

Email: privacy@soxaudit.ai

For urgent security concerns, contact security@soxaudit.ai