Is Dobby SOC 2 compliant?
Yes — immutable 365-day audit trails, AES-256 encryption, 3-level RBAC, and 7 SSO providers.
Updated Apr 18, 20264 viewssoc2compliancesecuritysso
SOC 2 compliance
Dobby is built for SOC 2 compliance:
- Immutable audit trails — 365-day retention, append-only.
- Encryption — AES-256-GCM for credentials, TLS 1.2+ everywhere.
- Access control — 3-level RBAC (Platform / Organization / Tenant) with fine-grained permissions.
- Enterprise SSO — 7 providers (Google, Okta, OneLogin, Microsoft Entra, Auth0, Ping, custom SAML/OIDC).
- Kill-switch — emergency stop tested quarterly.
- DR — daily backups, quarterly restore drills.
Visit the Trust Center (/trust) for the full security posture including our latest SOC 2 Type II report and sub-processor list.
Was this helpful?