Login Schedule demo
enterprise security & trust

Security you can trust.

EveryoneSocial protects customer data with a SOC 2 Type II attested security program, encryption in transit and at rest, and continuous monitoring. Detailed reports and documentation are available in our Trust Center.

Visit Trust Center Contact Security
audited & attested
SOC 2 Type IIAICPA
GDPREU
CCPACalifornia
01 — Certifications & attestations

Independent attestation. Globally recognized standards.

Our security program is independently audited and meets the requirements of the regulatory frameworks our customers rely on.

SOC 2 Type II
AICPA · Audited by Schellman & Company, LLC

The EveryoneSocial Platform is audited annually against the AICPA Trust Services Criteria for Security, Availability, and Confidentiality. Our most recent report covers the period May 1, 2024 through April 30, 2025. The full report is available to customers and prospects under NDA through our Trust Center.

GDPR
EU General Data Protection Regulation

We process personal data in accordance with the GDPR. A Data Processing Agreement and EU Standard Contractual Clauses are available to support compliant data transfers.

CCPA
California Consumer Privacy Act

We meet the requirements of the CCPA for handling personal information of California residents.

02 — Third-party penetration testing

Tested by independent experts. At least annually.

Independent penetration tests of the EveryoneSocial Platform are performed at least annually. A summary letter is available to customers under NDA through our Trust Center.

03 — Data protection

Customer data is protected end-to-end.

Encryption, access controls, and a SOC 2–audited hosting provider work together to keep customer data secure at every layer.

Encryption

Customer data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256.

Access controls

Access to production systems and customer data is restricted to authorized personnel based on role and business need. Access is enforced through SSO, multi-factor authentication, and least-privilege principles, and is logged and reviewed.

Hosting

The EveryoneSocial Platform is hosted on Amazon Web Services. AWS is a SOC 2–audited subservice organization.

04 — Platform security features

Customer-configurable controls.

The EveryoneSocial Platform gives administrators the controls they need to align with their identity, access, and compliance programs.

Single Sign-On

SAML 2.0 — centralized authentication through your identity provider.

SCIM

Automated user provisioning and de-provisioning from your identity provider.

Role-Based Access Control

RBAC aligns permissions with user roles to enforce least privilege.

Compliance & governance

Blocklist terms, mandatory disclosures, post moderation and approval, social media policy consent, external compliance system logging, and FINRA-compliant record storage and retention. Contact Sales for the full set of compliance and governance features.

05 — Monitoring & incident response

Continuously monitored. Plans tested annually.

The EveryoneSocial Platform is monitored continuously for security and availability events.

We maintain a documented incident response plan with defined roles, escalation paths, and customer notification procedures, tested at least annually.

06 — People & program

Security starts with our team.

Security training

All employees complete security and privacy training on hire and annually thereafter.

Background checks

Background checks are performed where permitted by law.

Policy program

Security policies are reviewed at least annually and acknowledged by personnel.

07 — Privacy

Privacy by design.

EveryoneSocial integrates privacy and data protection into the design of our platform and processes. We publish a Privacy Policy, offer a Data Processing Agreement aligned to GDPR, and support Standard Contractual Clauses for international data transfers. A current list of sub-processors is available in our Trust Center.

Data Protection Officer: dpo@everyonesocial.com

Reporting a security concern

To report a suspected vulnerability or security issue, please contact security@everyonesocial.com.

Trust Center

Documentation, available on demand.

Visit the EveryoneSocial Trust Center for our SOC 2 report, sub-processor list, Data Processing Agreement, Standard Contractual Clauses, and penetration test summary.