Skip to content

Is Dobby SOC 2 compliant?

Yes — immutable 365-day audit trails, AES-256 encryption, 3-level RBAC, and 7 SSO providers.

Updated Apr 18, 20264 viewssoc2compliancesecuritysso

SOC 2 compliance

Dobby is built for SOC 2 compliance:

  • Immutable audit trails — 365-day retention, append-only.
  • Encryption — AES-256-GCM for credentials, TLS 1.2+ everywhere.
  • Access control — 3-level RBAC (Platform / Organization / Tenant) with fine-grained permissions.
  • Enterprise SSO — 7 providers (Google, Okta, OneLogin, Microsoft Entra, Auth0, Ping, custom SAML/OIDC).
  • Kill-switch — emergency stop tested quarterly.
  • DR — daily backups, quarterly restore drills.

Visit the Trust Center (/trust) for the full security posture including our latest SOC 2 Type II report and sub-processor list.

Was this helpful?

Still need help?

Our team typically responds within one business day.

Submit a ticket →
Is Dobby SOC 2 compliant? — Dobby Help