# Trust & Security

> Review SuperDoc's SOC 2 controls, deployment model, data practices, infrastructure, and vulnerability disclosure program.



SuperDoc is SOC 2 Type II certified. Independent auditors verify security, privacy, and compliance controls. Drata continuously monitors more than 100 controls for security and GDPR compliance.

**SuperDoc Editor**, the JavaScript library, is open source and self-hosted. Your documents stay on your infrastructure. The SuperDoc team cannot access your content.

**SuperDoc APIs** are covered by SOC 2 controls and do not persist document data. Documents are processed and returned without persistent storage.

## SOC 2 report [#soc-2-report]

An independent auditor maintains the SOC 2 report, certifying the controls that protect your data.

The report follows the Trust Services Criteria from the AICPA's Assurance Services Executive Committee (ASEC). It evaluates the design and effectiveness of controls for security, availability, processing integrity, confidentiality, and privacy.

## Continuous control monitoring [#continuous-control-monitoring]

Drata monitors more than 100 security and privacy controls continuously, including GDPR compliance. Automated alerts and evidence collection verify SuperDoc's compliance posture.

## Team access and training [#team-access-and-training]

All employees use two-factor authentication, have role-based access restrictions, and sign a Non-Disclosure and Confidentiality Agreement. The team completes annual security training.

## Penetration tests [#penetration-tests]

SuperDoc works with independent security firms to perform annual network and application-layer penetration tests.

## Secure software development [#secure-software-development]

Manual and automated security checks run throughout the software development lifecycle.

## Data encryption [#data-encryption]

Data is encrypted in transit with Transport Layer Security (TLS) and at rest with AES-256 encryption.

## Infrastructure [#infrastructure]

SuperDoc's cloud infrastructure runs on Google Cloud Platform (GCP). Production data storage uses Google Spanner and Google Cloud Storage. GCP provides security, compliance, and auditing controls.

## Multi-region data storage and automated backups [#multi-region-data-storage-and-automated-backups]

Cloud data is stored across multiple regions within the United States. Automatic backups replicate data across multiple US data center locations.

## Compliance, audit logs, and monitoring [#compliance-audit-logs-and-monitoring]

Third-party monitoring detects potential attacks and anomalous network behavior. User actions in SuperDoc's cloud services are logged and auditable. GCP systems are regularly audited for ongoing security and compliance, including SOC 2.

## Terms of service and privacy policy [#terms-of-service-and-privacy-policy]

SuperDoc is dual-licensed. The open-source SuperDoc project is available under the [GNU AGPLv3](https://www.gnu.org/licenses/agpl-3.0). Proprietary and commercial deployments are licensed under the [SuperDoc Commercial License](https://www.superdocportal.dev/superdoc-terms-of-service).

Use of SuperDoc websites is governed by the [Website Terms of Use](https://app.termly.io/policy-viewer/policy.html?policyUUID=0b852fc9-5d9c-4170-8c96-08b072a55a9f).

See the [Privacy Policy](https://www.harbourshare.com/privacy-policy) for how SuperDoc handles data.

## Vulnerability disclosure program [#vulnerability-disclosure-program]

Found a security issue? Email [security@superdoc.dev](mailto:security@superdoc.dev). The security team investigates all reported issues promptly.
