Trust Center

Mycroft is a cybersecurity and compliance automation platform helping B2B SaaS companies manage security, risk, and compliance. We are committed to maintaining the security, privacy, and reliability of our platform, and hold SOC 2 Type 2 compliance (security, confidentiality, availability, and processing integrity) alongside being GDPR and HIPAA compliant (subject to DPA and BAA respectively). We encourage customers and prospects to review our security documentation, policies, and reports below.

Compliance

Compliance frameworks Mycroft currently meets or is working toward to uphold their security and privacy commitments.

SOC 2
Compliant
HIPAA
Compliant
GDPR
Compliant
ISO 42001
In progress
ISO 27001
In progress
CMMC Level 1
Compliant
CPCSC Level 1
Compliant
FedRAMP 20x - Class C
In progress
ISO 27701
In progress

Trusted by

Willful logoWillful
Wisedocs logoWisedocs
Weave logoWeave
Control D logoControl D
Superwhisper logoSuperwhisper
Cascade Debt logoCascade Debt

Resource library

Our security, compliance, and policy documentation, including audit reports.

SOC 2 Type 2 Report - 2026July 31, 2026
Application Penetration Test - 2026August 13, 2026
Mycroft Technologies Inc. - Validation TestAugust 13, 2026

Controls

Our security program is built on a complete set of controls that govern how we safeguard data and manage risk.

Infrastructure security
  • Tooling resources
  • AI system deployment
  • AI system technical documentation
Organizational security
  • Compliance Monitoring
  • Asset Inventory
  • Board of Directors/Advisors Established
Product security
  • Application Authentication
  • User Segregation
  • Role-based Access
Internal security procedures
  • Password Manager
  • Onboarding Checklist
  • Offboarding Checklist
Data and privacy
  • Password Standards
  • Resource documentation
  • Human resources

Subprocessors

Trusted third parties that support our services and may process customer data as part of their function.

GCP
CA/US
Cloudflare
CA/US
PropelAuth
US
1Password
CA
Google Workspace
US

Frequently asked questions

Updates

A live record of significant changes, vulnerability disclosures, and other notifications.

No updates as of August 7, 2026August 7, 2026

FedRAMP resources

Authorization data, documentation, and access records required for FedRAMP authorization and continuous monitoring, available to authorized federal parties.

FedRAMP 20x Certification Package Overview (FRC-CSO-PKG)

August 13, 2026

FedRAMP 20x Security Decision Record (SDR-CSO-FRR)

August 13, 2026

FedRAMP 20x Ongoing Certification Report (CCM-OCR-AVL)

August 13, 2026

FedRAMP 20x Certification Package Overview (Human Readable)

August 13, 2026

FedRAMP 20x Security Decision Record (Human Readable)

August 13, 2026

FedRAMP 20x Ongoing Certification Report (Human Readable)

August 13, 2026

SOC 2 Type 2

July 31, 2026

Powered by