Security, privacy, and compliance at SOX&AUDIT
We build SOX&AUDIT for audit teams that handle sensitive evidence. This page sets out the security controls in place today and the items on our enterprise readiness roadmap. Review our security practices, compliance status, and subprocessors below.
Last updated: 1 October 2026
Website
soxaudit.aiSecurity Contact
security@soxaudit.aiOur controls are being built toward the SOC 2 Trust Services Criteria; a formal SOC 2 audit is on our roadmap.
Connections use HTTPS (TLS), and the application and API send HSTS.
Access is limited by role, and each customer's data is kept apart by tenant. Sign-up is by invitation only.
Single sign-on (SSO) and multi-factor sign-in are available for enterprise deployments. SCIM provisioning is on our roadmap.
Enterprise deployment options, including dedicated cloud deployment (for example Microsoft Azure), are available for enterprise customers.
Independent penetration testing is on our roadmap. Security monitoring and alerting are being expanded as part of our enterprise readiness.
AI assists qualified professionals
AI outputs are tools to assist qualified professionals, not substitutes for professional judgment.
Named AI providers
AI processing uses OpenAI and OpenRouter, with TypeSafe for document classification. See the Subprocessors tab.
Customer data
Retained for the duration of the subscription. Customer data export and deletion processes are part of our enterprise readiness roadmap.
Audit logs
Audit log retention is part of our enterprise readiness roadmap.
Backups
Database backups run nightly to separate storage. Backup retention terms are being formalized as part of our enterprise readiness.