Socure Trust Center | Powered by Drata
Socure - General Business Insights
Documentation of our compliance against global standards including certifications, attestations, and audit reports.
SOC 2 Type 2 (SocureGov / Public Sector Environment)
SOC 2 Type 2 (Effectiv)
SOC 2 Type 2 (Commercial Environment)
ISO 27001 Attestation
BCDR Plan - India
BCDR Plan - United States (US)
End User License Agreement
EULA
Policies
- Exceptions Policy
- Data Classification Policy
- Contractor Policy
- Vulnerability Management Policy
- Vendor Management Policy
- Technology Export and Clean Device Travel Policy
- Security Incident Policy
- Security, Privacy Awareness, and Training Policy
Continuous monitoring
App Security
- Annual Penetration Test
- Code Review Process
- Employee Disclosure Process
- Quarterly Vulnerability Scan
- Responsible Disclosure (Bug Bounty)
- Software Development Lifecycle
- Vulnerability Management
- Web Application Firewall
Data Security
- Daily Database Backups
- Encryption at Rest
- Security Policies
- SSL/TLS Enforced
- System Access Control Policy
Infrastructure Security
- Cloud Data Storage Restricted
- Multiple Availability Zones
- Password Policy
- Security Patches Automatically Applied
Network Security
- Denial of Public SSH
- Firewalls
- Logging/Monitoring
- Malware Detection Software
- Unique Accounts Used
Organization Security
- Acceptable Use Policy
- BCDR Plan
- Code of Conduct
- Disaster Recovery Plan
- Incident Response Plan
- Incident Response Team
- Security Training
Product Security
- Hard-Disk Encryption
- MFA on Accounts
- Session Lock
- Terms of Service
Subprocessors
Please note: Additional subprocessors may be identified with Order Form/Contracts when adding specific services.
Amazon
Socure utilizes AWS for Hosting and IaaS. Data location: AWS US East
Google Cloud
IaaS provider for RiskOS(fmr. Effectiv), SaaS provider for Google suite and email Data location: US
Snowflake Inc
Socure utilizes Snowflake as a data warehouse. Data location: US
Topics and common questions
Socure is an online digital identity verification service. We are the leading platform for digital trust and authentication services. Our predictive analytics platform uses AI and machine learning to analyze in-house data and data obtained from third parties to verify identities in real time. Our identity verification platform is called ID+. Information about services ("modules") offered by ID+ as well as data elements in scope can be found on the Developer Hub (DevHub) at developer.socure.com.
Socure offers API integration in addition to a dashboard accessible via username and password or SSO via SAML 2.0.
Socure uses various sub-service providers (see Subprocessors section) for hosting and data warehousing services respectively, and leverages the use of data vendors, which are proprietary. Socure cannot legally disclose the names of its data vendors, but can provide categorical descriptions. Socure's data sources include internal and third-party (public and private) databases and services. Each is a well-established source that is vetted for freshness, accuracy and latency. They include:
- credit header and credit application data
- mobile network operators
- a wide variety of other records, including public data sources
- digital identity and fraud prevention verification services, including email, phone, address, IP, and social media intelligence services
- young/thin file demographics data
All third-party engagements are managed through Socure’s Vendor Management Program. We perform thorough due diligence exercises during onboarding and on an annual basis with all vendors.
Access is based on the principle of least privilege and need-to-know basis. Quarterly Access Reviews are conducted to ensure access is in line with roles and responsibilities.
All data resides within the geography of the United States, specifically within Socure's VPC in the AWS US East (Virginia) Region. In summary, the data physically never leaves the United States. Data can be accessed from outside the US via remote servers, depending on a valid documented business case. This access is based on the principle of least privilege and need-to-know basis. Additionally, Socure maintains a variety of security controls to prevent exfiltration of customer data including but not limited to a combination of host-based, cloud-based, and network DLP solutions.
Additional details
Socure is the gold standard for digital identity verification and identity fraud prevention. Founded in 2012, the company’s mission is to verify 100% of good identities in real-time and completely eliminate identity fraud on the internet.
Privacy details
Socure uses commercially reasonable physical, electronic, and procedural safeguards to protect information from loss, theft, misuse, unauthorized access, disclosure, alteration, and destruction, in accordance with applicable law, and we require our customers to do the same. Our security practices are also audited on a recurring basis, and we maintain ISO 27001 Certification and SOC 2 Type 2 Reports.