Trust

Security

Last updated September 11, 2026

How we protect the confidential data you and your firm trust us with, from encryption and access controls to how your content is used with AI.


01

Security at Socratics.ai

Security is foundational to Socratics.ai. Our platform handles some of the most sensitive material in a transaction, including data rooms, financial records, and the analyses built from them, so we designed it around the confidentiality that accounting firms and deal teams expect.

This page summarizes how we protect your information. It describes our practices and is not a contract; your agreement with us governs our commitments.

02

Compliance and certifications

Our controls are designed to meet the security and control requirements expected by accounting firms and their clients, and our program is aligned with recognized industry frameworks. Our SOC 2 Type II examination is [in progress].

[List available reports or certifications here and how customers can request them, for example under NDA.]

03

Encryption

Data is encrypted in transit using TLS and at rest using industry-standard encryption. Secrets and keys are managed through a dedicated key management service with restricted access.

04

Access controls

  • Access to production systems and customer data is limited to authorized personnel on a least-privilege basis.
  • Administrative access requires single sign-on and multi-factor authentication.
  • Access is role-based, reviewed regularly, and revoked promptly when no longer needed.
  • Actions on the platform are recorded to audit logs so activity can be traced.

05

Infrastructure and hosting

The platform runs on reputable cloud infrastructure located in the United States. Environments are logically isolated, and we maintain regular, encrypted backups to support recovery.

06

Your content and AI

We do not use Customer Content to train, fine-tune, or improve foundation models, and we contractually require the model providers we use not to train their models on data we send through their APIs. Where providers offer zero-retention processing, we use it.

Customer Content is processed only to deliver the work you request, and every calculation and step is recorded to an audit trail so results can be traced back to their source.

07

Sub-processors

We use a limited set of vetted sub-processors, including cloud hosting and infrastructure, large language model providers, product analytics, and email delivery, each bound by confidentiality and security obligations. A current list is available at [sub-processor list URL] or on request.

08

Monitoring and incident response

We monitor our systems for anomalies and maintain an incident response process for detecting, investigating, and responding to security events. If an incident affects your data, we will notify you as required by law and by our agreements with you.

09

Data retention and deletion

We retain Customer Content according to your agreement and configuration. On termination or on request, we delete or return Customer Content within [30] days, subject to any legal retention requirements.

10

Vulnerability disclosure

We welcome reports from security researchers. If you believe you have found a vulnerability, please contact us at support@socratics.ai with the details. Please give us a reasonable opportunity to investigate and address the issue before any public disclosure, and do not access or modify data that is not yours.

11

Security contact

For security questions, documentation requests, or to report a concern, contact us at support@socratics.ai.