What's already live. What's in flight.
We publish a working list of SOC 2 controls so security reviewers don't have to take our word for it. Every control below is mapped to a Trust Service Criterion (Security, Availability, Confidentiality, Processing Integrity, Privacy). No target dates — we'll let the attestation letter speak for the timeline.
- LiveTLS 1.2+ on every endpoint with HSTS preload
- LiveMongoDB Atlas AES-256 full-disk encryption at rest
- LiveBrowser-session credential vault — Fernet (AES-128 + HMAC) keyed by env-only secret
- LiveBcrypt password hashing (cost factor 12) + Firebase Google sign-in (JWKS-verified)
- LiveBrute-force protection — per-IP+email lockout after N failures
- LivePer-org and per-team authorization checks on every data endpoint
- LivePrivate Chief-of-Staff threads scoped to owner-user only
- LiveSecurity headers middleware (CSP, X-Frame-Options, Referrer-Policy)
- LiveSecrets in env only — no credentials in source control
- LiveCentralized superadmin action logging (actor, action, target, timestamp)
- LiveProof-of-integrity — every artifact SHA-256 anchored on Bitcoin via OpenTimestamps
- In progressMFA-required for all administrator accounts
- In progressQuarterly access reviews — formal sign-off log
- In progressVulnerability scanning in CI (Trivy / Snyk) — block on critical CVEs
- In progressDependency upgrade SLA (critical: 7d, high: 30d)
- In progressAnnual penetration test by external firm
- LiveManaged MongoDB Atlas with automated geo-replicated backups
- LiveEncrypted GridFS mirror for every uploaded file (durable through pod redeploys)
- LiveSupervisor-managed services with automatic restart on crash
- In progressExternal uptime monitoring + on-call rotation
- In progressDocumented Disaster Recovery (RPO/RTO) runbook + tabletop test
- In progressQuarterly backup-restore drill with timed evidence
- LivePer-org data isolation enforced at the query layer
- LiveCapability-URL-gated file serving (unguessable, scoped to org)
- In progressCustomer-managed encryption keys (BYOK) on Refine dedicated builds
- In progressData classification labels for every collection
- In progressData Loss Prevention scanning on outbound integrations
- LiveLLM call telemetry — every request logged with kind, model, tokens, latency, cost
- LiveMission event log — append-only audit trail per mission (think / tool_call / tool_result / artifact)
- LiveArtifact tamper-evidence — Bitcoin-anchored SHA-256 proofs
- LiveAnti-hallucination — agents auto-fetch user-supplied URLs as ground truth before responding
- LiveEmpty-promise detector + auto-retry forces same-turn artifact delivery
- In progressFormal change-management — PR review + deployment log linked to ticket
- LiveRight-to-erasure via full account deletion (cascades orgs, teams, conversations, files)
- LiveSub-processors disclosed publicly at /legal/sub-processors
- LiveStandard DPA available on request for every tier
- LivePrivacy policy + data retention windows published at /legal/privacy
- In progressPer-org data export (machine-readable JSON dump)
- In progressCookie-consent banner for marketing surfaces (EU/UK visitors)
- LiveIncident response contact + 24h acknowledgement SLA (team@archeforge.com)
- LiveSub-processor inventory maintained on a public page
- In progressDocumented incident response playbook (detection, containment, eradication, recovery, post-mortem)
- In progressVendor risk assessment for every sub-processor (annual review)
- In progressEmployee onboarding security training + acknowledgement
- In progressBackground checks for engineers with production access
- In progressAnnual policy review + version control on policy docs
- In progressCompliance automation platform — Vanta / Drata / Secureframe
SOC 2 Type II — on the roadmap for the dedicated build.
The shared platform's roadmap above is one stream of work. The other is the Refine reference build — a dedicated single-tenant deployment template we operate separately. When we engage an auditor it will be scoped to this template; once the Type II attestation lands, every Refine customer inherits the report under NDA without paying for their own audit. Until then, Refine customers get the dedicated deployment with all controls listed above operating today.
