Third Party Index

Snapshot 19636

Document
Security page
URL
https://everyonesocial.com/security/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
86358 bytes
SHA-256 (raw)
ded04c6a2f4540cd2f1ef3e659f5251fb6ff5116aadb9b155bf119492d144a6b
SHA-256 (normalized text)
137bc1e136a66ee7b147b6eb3d7418956cb8ab74ad0e5588805b838891d9fad9

Normalized text

Scripts and page chrome removed; this is what change detection compares.

enterprise security & trust
Security you can trust.
EveryoneSocial protects customer data with a SOC 2 Type II attested security program, encryption in transit and at rest, and continuous monitoring. Detailed reports and documentation are available in our Trust Center.
Visit Trust Center Contact Security
security & compliance
SOC 2 Type IIAICPA
GDPREU
CCPACalifornia
01 — Security & compliance
Independently attested. Contractually backed.
Our security program is independently audited to the SOC 2 Type II standard. For GDPR and CCPA, we support our customers' compliance through a Data Processing Agreement, Standard Contractual Clauses, and published policies.
SOC 2 Type II
AICPA · Audited by Schellman & Company, LLC
The EveryoneSocial Platform is audited annually against the AICPA Trust Services Criteria for Security, Availability, and Confidentiality. Our most recent report covers the period May 1, 2024 through April 30, 2025. The full report is available to prospects and customers under NDA through our Trust Center.
GDPR
EU General Data Protection Regulation
As a data processor, EveryoneSocial supports our customers' GDPR compliance. We offer a Data Processing Agreement and EU Standard Contractual Clauses to support lawful international data transfers.
CCPA
California Consumer Privacy Act
EveryoneSocial acts as a service provider under the CCPA and supports our customers in meeting their obligations for the personal information of California residents.
02 — Third-party penetration testing
Tested by independent experts. At least annually.
Independent penetration tests of the EveryoneSocial Platform are performed at least annually. A summary letter is available to prospects and customers under NDA through our Trust Center.
03 — Data protection
Customer data is protected at every layer.
Encryption, access controls, and a SOC 2–audited hosting provider work together to keep customer data secure at every layer.
Encryption
Customer data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256.
Access controls
Access to production systems and customer data is restricted to authorized personnel based on role and business need. Access is enforced through SSO, multi-factor authentication, and least-privilege principles, and is logged and reviewed.
Hosting
The EveryoneSocial Platform is hosted on Amazon Web Services. AWS is a SOC 2–audited subservice organization.
04 — Platform security features
Customer-configurable controls.
The EveryoneSocial Platform gives administrators the controls they need to align with their identity, access, and compliance programs.
Single Sign-On
SAML 2.0 — centralized authentication through your identity provider.
SCIM
Automated user provisioning and de-provisioning from your identity provider.
Role-Based Access Control
RBAC aligns permissions with user roles to enforce least privilege.
Social media compliance risk & governance
Available with the EveryoneSocial Compliance module: fully configurable to support LinkedIn capture, surveillance, and archive, with WORM record storage and retention designed to meet SEC Rule 17a-4 and support FINRA books-and-records obligations. Native API integration with Global Relay and SFTP delivery to Bloomberg Vault, through a pluggable archive layer built to onboard additional vendors. Tell us your archive of record and we will scope it. Contact Sales for the full set of Governance & Risk features.
05 — Monitoring & incident response
Continuously monitored. Plans tested annually.
The EveryoneSocial Platform is monitored continuously for security and availability events.
We maintain a documented incident response plan with defined roles, escalation paths, and customer notification procedures, tested at least annually.
06 — People & program
Security starts with our team.
Security training
All employees complete security and privacy training on hire and annually thereafter.
Background checks
Background checks are performed where permitted by law.
Policy program
Security policies are reviewed at least annually and acknowledged by personnel.
07 — Privacy
Privacy and data protection.
We build privacy and data protection into our platform and processes. We publish a Privacy Policy, offer a Data Processing Agreement aligned to GDPR, and support Standard Contractual Clauses for international data transfers. A current list of sub-processors is available in our Trust Center.
Data Protection Officer: [email protected]
Reporting a security concern
To report a suspected vulnerability or security issue, please contact [email protected].
Trust Center
Documentation, available on demand.
Visit the EveryoneSocial Trust Center for our SOC 2 report, sub-processor list, Data Processing Agreement, Standard Contractual Clauses, and penetration test summary.
Visit Trust Center