Skip to main content
Who can use this?
  • Compliance information is available to everyone, on all plans.
  • Roles: any role. Requesting the full SOC 2 report needs an authorised signatory for the NDA.
Gallabox holds a SOC 2 Type II attestation covering the Security, Availability, and Confidentiality Trust Services Criteria. This page lists what we’re attested against, what’s available to you, and how to get it.

SOC 2 Type II

Our controls were tested for both design and operating effectiveness across the full audit period. The audit covers the Gallabox platform and the applications, databases, and infrastructure that directly support it. We renew the attestation annually. Amazon Web Services and Heroku are our data centre subservice organisations. Their own controls sit outside our report; both maintain their own SOC 2 attestations.

How to get the report

The SOC 2 report is confidential and restricted-use, so we share it under NDA rather than publishing it.
1

Visit the Trust Vault

Go to trust.gallabox.com and select Get Access.
2

Sign the NDA

Access requires a signed NDA. An authorised signatory at your organisation needs to complete this.
3

Download what you need

Once approved, you can view our current SOC 2 report, control list, sub-processor list, and security policies.
If your procurement team needs something the Trust Vault doesn’t cover, email security@gallabox.com.

GDPR

Gallabox supports your GDPR obligations through the following commitments:
  • We act as your data processor. You remain the data controller for the customer data you process through Gallabox. See the Data Processing Agreement.
  • Standard contractual clauses are included in the DPA for transfers out of the EEA.
  • Sub-processors are disclosed and we give 30 days’ notice before adding or changing one. See Sub-processors.
  • Data subject requests — we assist you in responding to access, correction, and deletion requests, and in completing Data Protection Impact Assessments.
  • Breach notification — we notify you without undue delay if a personal data breach affects your data.
To put a DPA in place, contact support@gallabox.com.

Data deletion

Gallabox securely deletes customer data when your contract ends, under our Data Retention and Disposal Policy. This control is tested as part of our SOC 2 audit. See Data Security for detail on retention.

FAQs

Yes. Gallabox has a SOC 2 Type II report issued by an independent CPA firm covering January 16, 2025 to January 15, 2026, with no exceptions noted. You may see it referred to as an attestation, which is the formal term for a SOC 2 report. Request a copy at trust.gallabox.com.
Security, Availability, and Confidentiality. Processing Integrity and Privacy are not in scope for the current report.
No — the report is restricted-use, so an NDA is required. Our control summary and sub-processor list are available on the Trust Vault without one.
Not currently. Our information security management system follows ISO-aligned practices and is audited under SOC 2.
Yes. A third party performs vulnerability assessments and penetration tests at least annually, and identified vulnerabilities are remediated and re-verified. Summary results are available under NDA through the Trust Vault.
In the United States, on AWS and MongoDB Atlas, with backups distributed across multiple availability zones. If you have a specific data residency requirement, contact Gallabox support.