Casco

Casco provides autonomous security testing and penetration testing services for web apps, APIs, and AI systems.

Compliance

Compliance frameworks Casco currently meets or is working toward to uphold their security and privacy commitments.

SOC 2
Compliant
FedRAMP 20x - Class C
In progress

Resource library

Our security, compliance, and policy documentation, including audit reports.

SOC 2 Type 1 Report - 2025April 16, 2025
Penetration Test ReportMarch 10, 2026
SOC 2 Type 2 Attestation - 2025July 16, 2025
SOC 2 Type 2 Report - 2025July 16, 2025
SOC 2 Type 2 Report - 2026July 16, 2026
SOC 2 Type 2 Attestation - 2026July 16, 2026

Controls

Our security program is built on a complete set of controls that govern how we safeguard data and manage risk.

Infrastructure security
  • Vulnerability Management
  • Vendor Inventory
Organizational security
  • Background Checks
  • Trust Page
  • Threat Intelligence Management
Product security
  • Endpoint Encryption
  • Mobile Device Management
  • Role-based Access
Internal security procedures
  • Multi-factor Authentication
  • Incident Response Plan
  • Code of Conduct

Subprocessors

Trusted third parties that support our services and may process customer data as part of their function.

AWS
No location specified
WorkOS
No location specified
Anthropic
No location specified
OpenAI
No location specified
Daytona
No location specified

Updates

A live record of significant changes, vulnerability disclosures, and other notifications.

No major incidents as of August 26, 2026August 27, 2026

FedRAMP resources

Authorization data, documentation, and access records required for FedRAMP authorization and continuous monitoring, available to authorized federal parties.

FedRAMP 20x Certification Package Overview (FRC-CSO-PKG)

August 27, 2026

Powered by