Compliance
SOC 2 control alignment
Controls mapped to Trust Services Criteria - aligned, not attested, on this page.
Last updated January 15, 2026
SOC 2 overview
Bhogar designs and operates controls aligned with the AICPA Trust Services Criteria used in SOC 2 examinations. This page describes that alignment - not a completed audit or an available report. For the full security program and how we talk about compliance, see our Security trust centre.
- Framing
- We map platform controls to Security, Availability, Confidentiality, Processing Integrity, and Privacy criteria where they apply to our service.
- Audit status
- We do not publish or imply a SOC 2 Type I or Type II report on this site. Prospects and customers can ask security@bhogar.ai about current audit or attestation status under NDA.
- Trust centre
- Live control descriptions, data handling, and framework alignment are on the Security page - framed as implemented controls, not certifications.
Trust Services Criteria we align to
- Security (Common Criteria)
- Logical access, change management, incident response, risk assessment.
- Availability
- Monitoring, capacity planning, backups, disaster recovery, business continuity testing.
- Confidentiality
- Data classification, encryption, secure disposal, customer data segregation.
- Processing integrity
- Input validation, accurate processing, output reconciliation, schema migrations.
- Privacy
- Notice, choice and consent, collection, use, retention, disclosure, and disposal of personal information.
Representative controls
- Access management
- MFA, SSO via SAML/OIDC, role-based access, and session revocation.
- Change management
- Production changes through code review, automated tests, and CI/CD - no direct production access.
- Vulnerability management
- Dependency scanning, static analysis on changes, and periodic third-party security testing.
- Encryption
- TLS in transit, encryption at rest, and customer-managed keys (CMK/BYOK) for Enterprise deployments.
- Logging and monitoring
- Execution traces, administrative audit history, and telemetry through pluggable observability providers.
- Incident response
- Documented runbook, on-call coverage, and customer notification procedures.
- Vendor management
- Review of sub-processors with access to customer data.
- Business continuity
- Backups, disaster recovery planning, and documented recovery objectives for paid plans.
Ongoing assurance
- Control monitoring
- We continuously operate and review the controls described on the Security page - access, workspace separation, AI-specific guardrails, and audit trails.
- Security reviews
- Enterprise prospects can request a security questionnaire or architecture review through security@bhogar.ai.
- Penetration testing
- Periodic external testing; summaries may be shared under NDA when available - we do not publish pentest reports on this site.
Documentation requests
If you need a security questionnaire, architecture overview, or information about audit or attestation status, contact our security team. We do not offer self-serve SOC 2 report downloads from this marketing site.
- Enterprise and prospects
- Email security@bhogar.ai with your company name and the documents you need. We respond with what is available under NDA.
- Customers
- Use your account team or security@bhogar.ai for trust materials tied to your contract.
- No implied report
- Mention of SOC 2 on this page describes control alignment only - not an assertion that a report is available for download.
Security contact
Reach our security team at security@bhogar.ai. Disclosure policy and broader control descriptions are on our Security page.
Need trust materials under NDA?
We share security questionnaires, architecture overviews, and audit status in writing during your review - not implied by a badge on this site.