Socure Trust Center | Powered by Drata

Socure - General Business Insights

Documentation of our compliance against global standards including certifications, attestations, and audit reports.

SOC 2 Type 2 (SocureGov / Public Sector Environment)

SOC 2 Type 2 (Effectiv)

SOC 2 Type 2 (Commercial Environment)

ISO 27001 Attestation

BCDR Plan - India

BCDR Plan - United States (US)

End User License Agreement

EULA

Policies

Continuous monitoring

App Security

Data Security

Infrastructure Security

Network Security

Organization Security

Product Security

Subprocessors

Please note: Additional subprocessors may be identified with Order Form/Contracts when adding specific services.

Amazon

Socure utilizes AWS for Hosting and IaaS. Data location: AWS US East

Google Cloud

IaaS provider for RiskOS(fmr. Effectiv), SaaS provider for Google suite and email Data location: US

Snowflake Inc

Socure utilizes Snowflake as a data warehouse. Data location: US

Topics and common questions

Socure is an online digital identity verification service. We are the leading platform for digital trust and authentication services. Our predictive analytics platform uses AI and machine learning to analyze in-house data and data obtained from third parties to verify identities in real time. Our identity verification platform is called ID+. Information about services ("modules") offered by ID+ as well as data elements in scope can be found on the Developer Hub (DevHub) at developer.socure.com.

Socure offers API integration in addition to a dashboard accessible via username and password or SSO via SAML 2.0.

Socure uses various sub-service providers (see Subprocessors section) for hosting and data warehousing services respectively, and leverages the use of data vendors, which are proprietary. Socure cannot legally disclose the names of its data vendors, but can provide categorical descriptions. Socure's data sources include internal and third-party (public and private) databases and services. Each is a well-established source that is vetted for freshness, accuracy and latency. They include:

All third-party engagements are managed through Socure’s Vendor Management Program. We perform thorough due diligence exercises during onboarding and on an annual basis with all vendors.

Access is based on the principle of least privilege and need-to-know basis. Quarterly Access Reviews are conducted to ensure access is in line with roles and responsibilities.

All data resides within the geography of the United States, specifically within Socure's VPC in the AWS US East (Virginia) Region. In summary, the data physically never leaves the United States. Data can be accessed from outside the US via remote servers, depending on a valid documented business case. This access is based on the principle of least privilege and need-to-know basis. Additionally, Socure maintains a variety of security controls to prevent exfiltration of customer data including but not limited to a combination of host-based, cloud-based, and network DLP solutions.

Additional details

Socure is the gold standard for digital identity verification and identity fraud prevention. Founded in 2012, the company’s mission is to verify 100% of good identities in real-time and completely eliminate identity fraud on the internet.

Privacy details

Socure uses commercially reasonable physical, electronic, and procedural safeguards to protect information from loss, theft, misuse, unauthorized access, disclosure, alteration, and destruction, in accordance with applicable law, and we require our customers to do the same. Our security practices are also audited on a recurring basis, and we maintain ISO 27001 Certification and SOC 2 Type 2 Reports.

Privacy URL