Privacy Policy

Policy approved: 2026
    1. Introduction

    This Privacy Policy explains how Managed Security Services, LLC dba Cyber Security Services (“Cyber Security Services,” “we,” “us,” or “our”), operator of soc2audit.ai (the “Service”), collects, uses, discloses, and protects information about you when you use the Service, visit our marketing website at soc2audit.ai, or interact with us in any other way.

    We take privacy seriously. As a cybersecurity firm that helps other companies achieve SOC 2 attestation, we hold ourselves to the same standards we help our customers meet.

    If you have questions about this policy, contact us at privacy@soc2audit.ai.

    1. Who this policy applies to

    This Privacy Policy applies to:

    • Visitors to soc2audit.ai and its subdomains
    • Prospects who contact us or sign up for a trial
    • Customers who use the soc2audit.ai platform under a subscription agreement
    • End users whose data our customers upload to the Service (for example, employee user lists uploaded for access reviews, or vendor lists uploaded for vendor risk reviews)
    • Job applicants and other individuals who interact with us

    If you are an end user whose data was uploaded to the Service by one of our customers, that customer is the “controller” of your data and this policy explains how we act as their “processor.” Direct any data rights requests to the customer that uploaded your data.

    1. Information we collect

    3.1 Information you provide directly

    • Account information: name, email address, company name, job title, phone number, billing address
    • Authentication data: password hashes, multi-factor authentication tokens
    • Communications: any messages, support tickets, or content you send to us
    • Payment information: processed by our payment processor; we do not store full payment card numbers on our servers

    3.2 Information you upload to the Service

    Customers upload information to soc2audit.ai as part of running a SOC 2 program. This may include:

    • Gap assessment responses
    • Policies, procedures, and internal documentation
    • User lists (for access reviews) — typically name, email, role, access level, employment status
    • Vendor lists (for vendor risk reviews) — vendor name, contact, services purchased
    • Evidence artifacts (screenshots, logs, configuration exports)
    • Risk register entries and control observations

    We treat all uploaded content as confidential customer data.

    3.3 Information we collect automatically

    • Usage data: pages visited, features used, time spent, actions taken
    • Device and connection data: IP address, browser type and version, operating system, device identifiers, referring URL

    3.4 Information from third parties

    • Identity providers if you sign in via SSO (Google, Microsoft, Okta)
    • Payment processor to confirm billing status
    • Enrichment services to verify business email domains for anti-abuse purposes
    • Publicly available sources used by our AI Vendor Risk feature (breach databases, SOC 2 registries, corporate registries) — this data is about your vendors, not about you personally
    1. Legal bases for processing (GDPR)

    If you are in the European Economic Area, United Kingdom, or Switzerland, we process your personal data on one or more of the following bases:

    • Contract performance — to deliver the Service you subscribed to
    • Legitimate interests — to secure the Service, prevent fraud, improve our product, and communicate with prospects who requested information
    • Consent — for marketing emails and non-essential cookies (you can withdraw consent anytime)
    • Legal obligation — to comply with tax, accounting, and law-enforcement obligations
    1. How we use information

    We use the information we collect to:

    • Provide, operate, and maintain the Service
    • Run AI-guided gap assessments, policy generation, user access reviews, vendor risk reviews, and evidence collection workflows on behalf of our customers
    • Authenticate users and secure accounts
    • Process payments and manage subscriptions
    • Communicate with you about the Service, including security notices and product updates
    • Provide customer support
    • Improve the Service, including training AI models — but see Section 6 for how we handle customer data in AI training
    • Detect, investigate, and prevent fraudulent, abusive, or unauthorized activity
    • Comply with legal obligations
    1. AI and customer data

    soc2audit.ai uses AI to assist with gap assessments, policy generation, user access reviews, vendor risk reviews, and evidence recommendations.

    Our commitments

    • We do not use customer content to train foundation models. Customer policies, gap assessment responses, uploaded evidence, and other content you provide are not used to train general-purpose AI models, and are not shared with third-party AI vendors for training purposes.
    • We may use aggregated, de-identified data to improve our own models and product analytics. This data cannot be linked back to any individual or customer.
    • Third-party AI providers. We use large language model APIs (currently OpenAI and Anthropic, subject to change) to power certain features. These providers process customer content under enterprise agreements that prohibit training on our submissions. A current list of AI subprocessors is available at soc2audit.ai/subprocessors.
    • You can opt out of certain AI features through your account settings. Some features require AI to function and cannot be disabled without disabling the feature itself.
    1. How we share information

    We share information only in the following circumstances:

    • With your consent. For example, when you connect a third-party integration.
    • With service providers (subprocessors). Hosting, payment processing, email delivery, error monitoring, and AI providers. All subprocessors are contractually required to protect your data and use it only to provide services to us. A current subprocessor list is available at soc2audit.ai/subprocessors.
    • With your AICPA-licensed audit partner. When you designate a CPA firm as your auditor within soc2audit.ai, we provide them read-only access to your evidence and control status. This is a core function of the Service.
    • With Cyber Security Services personnel delivering an add-on service you explicitly engaged (pen testing, vulnerability management, virtual CISO).
    • For legal reasons. When required by law, court order, or to protect the rights, property, or safety of our customers, us, or others.
    • In a business transaction. If we are involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. You will be notified before your information becomes subject to a different privacy policy.

    We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

    1. Your privacy rights

    Depending on where you live, you may have some or all of the following rights:

    • Right to access your personal information
    • Right to correct inaccurate information
    • Right to delete your information
    • Right to portability — receive a copy of your data in a machine-readable format
    • Right to opt out of certain uses of your information
    • Right to non-discrimination for exercising these rights
    • Right to withdraw consent (where processing is based on consent)

    To exercise any of these rights, email privacy@soc2audit.ai or use the in-app privacy controls under Account Settings → Privacy. We will respond within the timeframes required by applicable law (30 days for GDPR, 45 days for CCPA/CPRA).

    If you are an end user whose data was uploaded to the Service by one of our customers (for example, you are an employee of a soc2audit.ai customer whose data appears in a user access review), please direct your rights request to that customer. We will assist them in responding.

    California residents: you have additional rights under CCPA/CPRA including the right to know categories of information collected and shared. In the last 12 months we have collected and shared the categories of information described in Section 3 for the purposes described in Section 5.

    Nevada residents: you may opt out of the sale of personal information. We do not sell personal information.

    1. Data retention

    We retain personal information for as long as your account is active and for a reasonable period afterward to comply with legal, tax, and accounting obligations. Typical retention:

    • Account data: duration of subscription + 3 years
    • Uploaded customer content: duration of subscription; deleted within 90 days of account closure unless you request longer retention for audit continuity
    • Billing records: 7 years (tax law requirement)
    • Marketing communications data: until you unsubscribe + 12 months
    • Log data: 12 months for security investigations

    You can request earlier deletion at any time (see Section 8).

    1. Security

    We implement administrative, technical, and physical safeguards designed to protect your information. These include:

    • Encryption in transit (TLS 1.2+) and at rest (AES-256)
    • Multi-factor authentication for all soc2audit.ai personnel
    • Role-based access controls with least-privilege enforcement
    • Continuous security monitoring and logging
    • Annual penetration testing and vulnerability scanning
    • Employee security training and background checks

    For a full description of our security program, see our Security Policy at soc2audit.ai/security.

    No system is 100% secure. If we become aware of a security incident affecting your data, we will notify you as required by applicable law.

    1. International data transfers

    soc2audit.ai hosts customer data in Microsoft Azure data centers located in the United States. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States.

    For transfers of personal data from the European Economic Area, United Kingdom, or Switzerland, we rely on:

    • Standard Contractual Clauses approved by the European Commission
    • Additional safeguards including encryption, access controls, and contractual restrictions on subprocessors

    Contact privacy@soc2audit.ai for a copy of the Standard Contractual Clauses.

    1. Children’s privacy

    soc2audit.ai is a business-to-business service and is not directed to individuals under 16. We do not knowingly collect personal information from children under 16. If we learn we have collected such information, we will delete it.

    1. Third-party links

    Our website may contain links to third-party sites. This Privacy Policy does not apply to those sites. We encourage you to review the privacy policies of any third-party sites you visit.

    1. Changes to this Privacy Policy

    We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or in-app notification at least 30 days before the changes take effect. The “Last updated” date at the top of this policy indicates when it was last revised.

    1. Contact us

    Managed Security Services, LLC dba Cyber Security Services

    Attn: Privacy

    Westerville, Ohio, United States

    Email: privacy@soc2audit.ai

    Data Protection Officer: privacy@soc2audit.ai