Security and Compliance
Updated 30 July 2025
At Superdone, we take the security and privacy of your data seriously. While we are not yet SOC 2 certified, we follow industry-standard practices to ensure the safety, confidentiality, and integrity of your data.
Our Security Approach
We adhere to strong security protocols across all aspects of our platform:
-
Data Encryption: All data is encrypted in transit (TLS 1.2 or higher) and at rest using AES-256.
-
Access Controls: We use role-based access controls (RBAC) to ensure that only authorized team members can access specific systems or data.
-
Authentication: We support secure authentication protocols including SSO (Single Sign-On) and multi-factor authentication (MFA) where applicable.
-
Audit Logging: Key actions and changes in the system are logged and monitored for suspicious or unauthorized behavior.
-
Infrastructure: Our platform is hosted on secure, industry-leading cloud infrastructure with built-in redundancy, disaster recovery, and physical security.
-
Penetration Testing: We engage independent security firms to perform regular vulnerability and penetration testing of our systems.
Data Privacy and Compliance
-
Data Residency: Your data is hosted in secure, US-based data centers.
-
GDPR Alignment: We are aligned with the principles of GDPR and provide tools for customers to access or delete their data on request.
-
Meeting Data: When Superdone joins meetings, only authorized users can view or manage meeting summaries and related content. We never share or sell your data.
-
Customer Controls: Customers can manage integrations, data access, and permissions through the Superdone interface.
Commitment to Earning Your Trust
We understand that compliance certifications like SOC 2 are important. While we don’t yet hold formal certification, we are actively preparing to undergo the SOC 2 audit and will update this page as soon as certification is complete.
If you have additional questions about our security posture, need to complete a vendor security questionnaire, or require a DPA (Data Processing Agreement), please contact our support team.
Didn't answer your question? We can help.
Contact us