How we protect your data and maintain the security of our platform.
Last updated: December 2025
We operate a SOC 2 Security-aligned security program with documented policies, enforced controls, and supporting evidence.
Enterprise-grade security at every layer.
Defense in depth for your compliance data.
Secure password hashing (bcrypt), optional SAML SSO for enterprise
Role-based access control with jurisdiction-level data isolation
Secure, HTTP-only cookies with automatic expiration
External penetration testing, automated dependency scanning, and security updates
Secure processes from development to production.
We carefully select vendors based on their security posture.
| Service | Certification |
|---|---|
| Cloud Storage | SOC 2 Type II |
| Email Delivery | SOC 2 Type II |
| Secrets Management | SOC 2 Type II |
| Authentication (SSO) | SOC 2 Type II |
| Infrastructure | ISO 27001 |
Our security program is designed to meet the requirements of:
For security questionnaires, penetration test reports, or detailed security documentation:
security@citycycle.appTo report a security vulnerability, email us at the address above. We take all reports seriously and will respond promptly.
Contact Us