Third Party Index

Snapshot 49624

Document
Security page
URL
https://www.cometly.com/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
305280 bytes
SHA-256 (raw)
b77ef58460b8ddc3c43f4aa18caea85ed6c8cb76a51066eee19730fff2d751e3
SHA-256 (normalized text)
e8c2be7a5857bca795bc14ab0c97f0e57efdf4fcee6bea9955841f3f000e5587

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Agent is live— ask anything about your dataMeet Agent
Security & Trust
Security built for
revenue data.
Cometly handles the data your finance, sales, and marketing teams run on, Stripe revenue, CRM pipeline, and ad-platform spend. We treat it the way you do: with strict access controls, processes we are preparing for independent SOC 2 audit, and encryption at every layer.
Request security packetContact security
Trust Center
SOC 2 in progress
Encryption
AES-256 · TLS 1.2+
Compliance
SOC 2 in progress · GDPR · DPA
Identity
RBAC · 2FA · Audit logs
Status
Incident communications by email
Compliance
SOC 2 in progress. Continuously monitored.
SOC 2 Type 1 and Type II are in progress. We are working toward SOC 2 using the Delve compliance platform. Our DPA, sub-processor list, and security questionnaire responses are available on request.
SOC 2In progress
SOC 2 Type 1
We are working toward SOC 2 using the Delve compliance platform. Our DPA, sub-processor list, and security questionnaire responses are available on request.
SOC 2In progress
SOC 2 Type II
Continuous evaluation of our security controls over an extended period, following completion of our Type 1 audit. Reach out for our latest timeline.
GDPR
GDPR
EU data subject rights, lawful basis tracking, and a published Data Processing Addendum.
CCPA
CCPA / CPRA
California consumer rights honored, including access, deletion, and opt-out of sale or sharing.
PCIHandled by Stripe
Payments (PCI DSS handled by Stripe)
We never store raw card data. All payments are processed by Stripe, a Level 1 service provider.
ISORoadmap
ISO 27001
On our compliance roadmap following SOC 2 completion.
To request our security questionnaire responses, sub-processor list, or DPA, email [email protected].
How we protect you
Defense at every layer of the stack.
From the browser request to the row in our database, every layer of Cometly is built with security primitives that scale with your team and your traffic.
01, Data
Your data, encrypted and isolated.
AES-256 at rest. TLS 1.2+ in transit. Per-workspace logical isolation. Integration credentials (OAuth tokens, export secrets) are additionally encrypted at the application layer.
02, Identity
Strong authentication, by default.
Role-based permissions on every workspace, optional two-factor authentication, and audit logging of all AI and MCP tool calls, retained 90 days. Broader workspace audit logging is on our roadmap.
03, Infrastructure
Resilient cloud, by design.
Hosted in US regions on Laravel Cloud, AWS, and SingleStore Helios, whose infrastructure holds SOC 2 and ISO 27001 certifications. Production data is segregated from staging, with automated backups for resiliency.
04, Operations
Continuous monitoring and scanning.
Continuous automated monitoring and audit logging. Continuous automated code and dependency scanning, and a responsible disclosure program with the security community.
Data protection
Encrypted, isolated, and yours alone.
Your customer data never co-mingles with another workspace. Every read and write is scoped to your tenant, and we test that boundary continuously.
Encryption at rest
All data is encrypted at rest with AES-256 by our infrastructure providers, including primary databases, backups, and object storage.
Encryption in transit
TLS 1.2 or higher, enforced at the edge.
Application-layer encryption
Integration credentials (OAuth tokens, export secrets) are additionally encrypted at the application layer.
Key management
Encryption at rest is provided and key-managed by our infrastructure providers (SingleStore, AWS, Laravel Cloud). Cometly does not hold customer-data encryption keys.
Backups
Automated encrypted backups managed by SingleStore and Laravel Cloud.
Tenant isolation
Every workspace is logically isolated. Queries are scoped to your workspace at the application layer.
Application security
Right access. Right people. Right log.
Identity and access are the foundation of trust. Cometly gives your IT and security teams the controls they expect, and the audit trail they need.
Role-based access control
Owner, Administrator, and Member roles at the account level; Administrator, Advertiser, and Viewer roles at the workspace level.
Sessions & 2FA
Sessions expire after 120 minutes of inactivity. Optional two-factor authentication (TOTP) is available to every user.
Audit logs
Audit logging of all AI and MCP tool calls, retained 90 days. Broader workspace audit logging is on our roadmap.
API key scoping
Scoped, revocable API keys for controlled programmatic access.
Infrastructure
Built on infrastructure your security team already trusts.
We run on Laravel Cloud, AWS, and SingleStore Helios in US regions, on infrastructure that holds SOC 2 and ISO 27001 certifications.
Audited infrastructure providers
Hosted in US regions on Laravel Cloud, AWS, and SingleStore Helios, whose infrastructure holds SOC 2 and ISO 27001 certifications.
Network protection
Traffic is fronted by Cloudflare for DDoS mitigation and edge protection, with application-level rate limiting.
Segregated environments
Production data is segregated from staging and development environments.
Vulnerability management
Continuous dependency and static code scanning via Aikido, with findings triaged and tracked to remediation.
Penetration testing
A third-party penetration test is planned as part of our SOC 2 program. Continuous automated scanning (Aikido) runs today.
Backup and restore
Documented backup and restore procedures.
Privacy & data rights
Privacy is a control surface, not a checkbox.
Cometly is built so the privacy promises you make to your customers stay enforceable end-to-end. From signed DPAs to in-product deletion tools, the controls are first-class.
Data Processing Addendum
Pre-signed DPA with Standard Contractual Clauses, available without negotiation for every customer.
Data subject requests
Documented processes to honor access, rectification, deletion, and export requests.
Sub-processors
Public sub-processor list, with 30-day advance notice of any additions or material changes.
Data residency
US data stays in US regions. Contact us about data residency requirements.
Customer-owned data
You own your data. Export anytime, and we'll permanently delete on request, typically within 30 days.
Privacy policy
What we collect, why, and your rights.
DPA
Pre-signed DPA with SCCs.
Sub-processors
Current vendors and providers.
Operations & people
Security is everyone's job, not a department.
The strongest controls are the ones a team actually lives. Our policies, training, and reviews are built to keep security at the top of mind for every Cometly engineer.
Continuous monitoring
Continuous automated monitoring (Sentry, Aikido) with alerting to the engineering team.
Annual security training
As part of our SOC 2 program, every Cometly employee completes security and privacy training annually.
Background checks
As part of our SOC 2 program, we are formalising pre-employment background checks where legally permitted. All employees sign confidentiality agreements before access.
Least-privilege access
Production access is gated and logged. As part of our SOC 2 program, we are formalising quarterly access reviews.
Vendor reviews
As part of our SOC 2 program, we are formalising security reviews of every sub-processor before adoption and annually thereafter.
Incident response
Documented IR runbooks with defined severity levels. Customers are notified without undue delay for incidents that affect them.
Responsible disclosure
Found something? We want to hear from you.
We work with the security research community and welcome reports of potential vulnerabilities. Reports made in good faith, with no impact on customer data, won't be subject to legal action.
[email protected]
When you report
We aim to acknowledge reports within two business days.
We triage each report and keep you informed as the fix progresses through review and deploy.
We appreciate and acknowledge good-faith reports from the security community.
FAQ
The questions security teams ask us.
Need something not covered here? Email our security team and we'll get back to you.
Email security
Where is Cometly on SOC 2?
Both SOC 2 Type 1 and SOC 2 Type II are in progress. We are working toward SOC 2 using the Delve compliance platform. Our DPA, sub-processor list, and security questionnaire responses are available on request so your security team can start their review today. Email [email protected] to request the packet.
Do you offer a Data Processing Addendum (DPA)?
Yes. We have a pre-signed DPA with EU Standard Contractual Clauses available to every customer, no negotiation required. Enterprise customers can request a counter-signed version.
Where is my data stored?
Data is hosted in US regions on Laravel Cloud, AWS, and SingleStore Helios, whose infrastructure holds SOC 2 and ISO 27001 certifications. Contact sales to scope data residency requirements.
How is my data encrypted?
All data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Encryption at rest is provided and key-managed by our infrastructure providers (SingleStore, AWS, Laravel Cloud); Cometly does not hold customer-data encryption keys. Integration credentials (OAuth tokens, export secrets) are additionally encrypted at the application layer.
Do you support SSO and SAML?
Not yet — SSO and SAML are on our roadmap. Today, every workspace ships with role-based access control, optional two-factor authentication (TOTP), and audit logging of all AI and MCP tool calls, retained 90 days. Email [email protected] to discuss your IdP requirements.
Are you GDPR and CCPA compliant?
Yes. Cometly supports the data subject rights required under GDPR and CCPA and has documented processes for access, deletion, and export requests.
How do you handle security incidents?
We follow a documented incident response plan with defined severity levels and escalation paths. Customers affected by an incident are notified without undue delay, with details and remediation steps.
Do you conduct penetration tests?
Not yet. We run continuous automated scanning (Aikido) today and plan a third-party penetration test as part of our SOC 2 program.
Where can I report a security issue?
Email [email protected] for sensitive reports. We aim to acknowledge reports within two business days.
Need to pass security review?
We'll send our SOC 2 program documentation, DPA, and security questionnaire responses in one bundle.
Email securityTalk to sales