SOCRadar

SOCRadar

Trust Center

SOCRadar is an Extended Threat Intelligence (XTI) company.

Our cloud platform brings Cyber Threat Intelligence, External Attack Surface Management, Digital Risk and Brand Protection, Dark Web Monitoring and Supply Chain Intelligence together in a single view for customers across the Americas, EMEA and APAC.

Customers trust us with sensitive information about their digital assets, exposures and potential compromises, so our own security posture is part of the product.

SOCRadar operates an ISO/IEC 27001:2022 certified Information Security Management System, holds SOC 2 Type I and Type II reports covering all five Trust Services Criteria, is listed on the CSA STAR Registry for both cloud security and AI, and runs its privacy program in line with GDPR and CCPA.

Use this Trust Center to review our certifications, security controls and subprocessors, and to request the reports and policies you need for your vendor assessment.

Confidential documents are shared under NDA.

For security or privacy questions, contact [email protected].

Resources

Policies, security documentation, and audit-ready evidence. Private items unlock through the access-request flow.

Documents

7 items
  • Certificate ISMS-26-0106-SOC issued by KIOSCERT, valid until 31 May 2027.

    View
  • SOC 2 Type II Report (2025) 1ResourcePrivate

    Independent auditor's report on design and operating effectiveness, 1 Dec 2024 to 30 Nov 2025, all five Trust Services Criteria. Available on request under NDA.

  • SOC 2 Type I Report (2025) 1ResourcePrivate

    Auditor's report on the design of SOCRadar's controls as of 30 Nov 2025. Available under NDA.

  • Penetration Test Attestation (2026) 1ResourcePrivate

    Independent 2026 web application pentest by OrbisGuard; all findings verified as remediated.

  • Data Processing Agreement (DPA) 1ResourcePrivate

    SOCRadar's standard DPA: processing instructions, security measures, subprocessors and government access.

  • Current sub-processor register (DP 02, rev. 02) including EU and US hosting regions.

    View
  • One-page public summary of SOCRadar's certifications, hosting, encryption, access controls, resilience, vulnerability management, and privacy practices.

    View

Policies

9 items
  • Information Security Policy 1ResourcePrivate

    Top-level policy for protecting SOCRadar's information assets: roles, asset management, access control, incident response and compliance.

  • Log Management Policy 1ResourcePrivate

    How system and application logs are generated, protected, retained and reviewed.

  • Vendor Management Policy 1ResourcePrivate

    How SOCRadar selects, assesses, contracts and reviews vendors and third-party service providers.

  • Incident Management Program 1ResourcePrivate

    How SOCRadar detects, triages, contains and reports security incidents, including customer notification.

  • Access Management Policy 1ResourcePrivate

    How access to SOCRadar systems and data is requested, approved, reviewed and revoked.

  • Business Continuity Plan Test Results 1ResourcePrivate

    Executive overview of SOCRadar's business continuity plan test covering the Delaware HQ and Istanbul office.

  • Data Encryption and Key Management Policy 1ResourcePrivate

    Encryption standards for data at rest and in transit, and how cryptographic keys are managed.

  • Disaster Recovery Plan 1ResourcePrivate

    How SOCRadar restores critical systems and data after a disruption, with recovery roles and objectives.

  • AI Governance & Responsible AI Policy 1ResourcePrivate

    How SOCRadar governs AI across its lifecycle: risk assessment, responsible AI principles, human oversight, data governance, model security, and third-party AI due diligence. Aligned with the CSA AI Controls Matrix.