Socero Inc. protects the data that customers entrust to the SAA Cloud API. This Security and Trust Center summarizes our security posture, the technical and organizational measures we maintain, and how to report a suspected vulnerability. For our contractual data-protection commitments to customers, see our Data Processing Addendum.
Our approach
Security is built into the design of the service rather than added afterward. We apply defense in depth, so a failure of any single control does not compromise customer data, and we follow the principle of least privilege across our systems and our team. We do not retain raw audio or video beyond the duration necessary to process each API request, which limits the data at risk in the first place.
Data protection and encryption
Data is encrypted in transit using current Transport Layer Security, and data stored on our behalf is encrypted at rest. Encryption keys are managed through controlled key-management practices with restricted access. Where applicable, customer environments are logically segregated so one customer cannot access another customer's data.
Access control
Internal access to systems and data is governed by role-based access control and the principle of least privilege. Access to production systems requires multi-factor authentication, is granted only to personnel who need it for their role, and is reviewed periodically. Administrative access is logged for accountability.
Network and infrastructure security
The SAA Cloud API is hosted with reputable cloud infrastructure providers that operate physically secure facilities. We use network segmentation and firewalls to isolate sensitive systems, apply protections against common web and API attacks, and enforce rate limiting and abuse prevention to keep the service available for all users.
Application security
We follow secure development practices throughout the lifecycle, including peer code review, dependency and vulnerability management, and disciplined secrets management so credentials are never embedded in code. Changes are tested before release.
Monitoring and logging
We maintain centralized logging and monitor for anomalous activity, with alerting so our team can respond quickly. Security-relevant logs are retained for a period sufficient to support investigation and analysis.
Incident response and breach notification
We maintain a documented incident response process covering detection, containment, eradication, recovery, and review. In the event of a security incident affecting customer data, we will notify affected customers without undue delay. Where our Data Processing Addendum applies, we will provide notification within the timelines stated there.
Business continuity
We maintain backups, redundancy, and recovery procedures designed to restore service and protect data after a disruption. Recovery procedures are reviewed so we can act on them when needed.
Personnel security
Our personnel are bound by confidentiality obligations and receive security awareness guidance appropriate to their roles. We conduct background checks where permitted by applicable law.
Sub-processors and vendor management
We use a limited set of vetted sub-processors to operate the service, each engaged under appropriate data-protection terms. The current list of sub-processors is maintained on our Sub-processors page.
Compliance
We design our controls with reference to recognized security frameworks and to applicable data-protection law, including the General Data Protection Regulation (GDPR), the UK GDPR, and the Personal Information Protection and Electronic Documents Act (PIPEDA). We support customer security due diligence and can provide further documentation under agreement.
Responsible disclosure
We welcome reports of suspected vulnerabilities in our services. Please report any security concern to [email protected] and give us a reasonable opportunity to investigate and remediate before any public disclosure. While testing, please do not access or modify other users' data, degrade or disrupt the service, or exfiltrate data. We will acknowledge credible reports and work with you in good faith.
Contact
For security matters and vulnerability reports, contact [email protected]. For compliance documentation and due-diligence requests, contact [email protected].
To request our current security documentation, contact [email protected].