> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gallabox.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance

> Gallabox's SOC 2 Type II attestation, GDPR commitments, and how to request our security documentation.

> **Who can use this?**
>
> * Compliance information is available to everyone, on all plans.
> * Roles: any role. Requesting the full SOC 2 report needs an authorised signatory for the NDA.

<Info>
  Gallabox holds a SOC 2 Type II attestation covering the Security, Availability, and Confidentiality Trust Services Criteria. This page lists what we're attested against, what's available to you, and how to get it.
</Info>

## SOC 2 Type II

| Item                    | Detail                                       |
| ----------------------- | -------------------------------------------- |
| Report type             | SOC 2 Type II                                |
| Trust Services Criteria | Security, Availability, Confidentiality      |
| Audit period            | January 16, 2025 to January 15, 2026         |
| Auditor                 | An independent CPA firm, named in the report |
| Result                  | No exceptions noted                          |

Our controls were tested for both design and operating effectiveness across the full audit period. The audit covers the Gallabox platform and the applications, databases, and infrastructure that directly support it. We renew the attestation annually.

Amazon Web Services and Heroku are our data centre subservice organisations. Their own controls sit outside our report; both maintain their own SOC 2 attestations.

### How to get the report

The SOC 2 report is confidential and restricted-use, so we share it under NDA rather than publishing it.

<Steps>
  <Step title="Visit the Trust Vault">
    Go to [trust.gallabox.com](https://trust.gallabox.com) and select **Get Access**.
  </Step>

  <Step title="Sign the NDA">
    Access requires a signed NDA. An authorised signatory at your organisation needs to complete this.
  </Step>

  <Step title="Download what you need">
    Once approved, you can view our current SOC 2 report, control list, sub-processor list, and security policies.
  </Step>
</Steps>

If your procurement team needs something the Trust Vault doesn't cover, email [security@gallabox.com](mailto:security@gallabox.com).

## GDPR

Gallabox supports your GDPR obligations through the following commitments:

* **We act as your data processor.** You remain the data controller for the customer data you process through Gallabox. See the [Data Processing Agreement](/privacy-and-security/dpa).
* **Standard contractual clauses** are included in the DPA for transfers out of the EEA.
* **Sub-processors are disclosed** and we give 30 days' notice before adding or changing one. See [Sub-processors](/privacy-and-security/subprocessors).
* **Data subject requests** — we assist you in responding to access, correction, and deletion requests, and in completing Data Protection Impact Assessments.
* **Breach notification** — we notify you without undue delay if a personal data breach affects your data.

To put a DPA in place, contact [support@gallabox.com](mailto:support@gallabox.com).

## Data deletion

Gallabox securely deletes customer data when your contract ends, under our Data Retention and Disposal Policy. This control is tested as part of our SOC 2 audit. See [Data Security](/privacy-and-security/data-security) for detail on retention.

## FAQs

<AccordionGroup>
  <Accordion title="Is Gallabox SOC 2 certified?">
    Yes. Gallabox has a SOC 2 Type II report issued by an independent CPA firm covering January 16, 2025 to January 15, 2026, with no exceptions noted. You may see it referred to as an attestation, which is the formal term for a SOC 2 report. Request a copy at [trust.gallabox.com](https://trust.gallabox.com).
  </Accordion>

  <Accordion title="Which Trust Services Criteria does the report cover?">
    Security, Availability, and Confidentiality. Processing Integrity and Privacy are not in scope for the current report.
  </Accordion>

  <Accordion title="Can I get the report without signing an NDA?">
    No — the report is restricted-use, so an NDA is required. Our control summary and sub-processor list are available on the Trust Vault without one.
  </Accordion>

  <Accordion title="Is Gallabox ISO 27001 certified?">
    Not currently. Our information security management system follows ISO-aligned practices and is audited under SOC 2.
  </Accordion>

  <Accordion title="Do you run penetration tests?">
    Yes. A third party performs vulnerability assessments and penetration tests at least annually, and identified vulnerabilities are remediated and re-verified. Summary results are available under NDA through the Trust Vault.
  </Accordion>

  <Accordion title="Where is my data stored?">
    In the United States, on AWS and MongoDB Atlas, with backups distributed across multiple availability zones. If you have a specific data residency requirement, contact Gallabox support.
  </Accordion>
</AccordionGroup>

## Related Articles

* [Data Security](/privacy-and-security/data-security) — the controls behind the attestation
* [Data Processing Agreement (DPA)](/privacy-and-security/dpa) — Gallabox as a data processor
* [Sub-processors](/privacy-and-security/subprocessors) — third-party services Gallabox uses
* [Account Security Overview](/settings/security) — 2FA, activity log, IP restrictions
