Security & trust

Your data deserves the same
obsessive care we give our own.

Manager.Social is the system of record for thousands of marketing teams. We treat that responsibility the way a bank treats deposits — with engineering rigor, independent audits, and zero shortcuts. Encryption everywhere, access only to those who need it, and a public posture you can verify.

Audited & certified
SOC 2
Type II
ISO
27001:2022
GDPR
Compliant
HIPAA
BAA available
PCI DSS
Level 1
CCPA
Compliant
Five pillars

How we protect everything you put in.

Defense in depth, applied to every layer of the stack. From the disk your data lives on to the tab you open it in — each layer hardened, monitored, and independently verified.

Encryption

  • AES-256-GCM at rest, on every disk, every backup
  • TLS 1.3 in transit, with HSTS preloaded and PFS
  • Per-tenant keys rotated quarterly via AWS KMS
  • Customer-managed keys (BYOK) on Enterprise plan

Access control

  • SSO + SAML 2.0 with Okta, Azure AD, Google Workspace, JumpCloud
  • SCIM auto-provisioning & deprovisioning
  • Mandatory 2FA with TOTP, WebAuthn / passkeys
  • Granular RBAC — 12 default roles + custom roles

Infrastructure

  • AWS primary (us-east-1, eu-west-1, ap-southeast-1)
  • Multi-AZ with automated failover under 60s
  • Hourly snapshots, 30-day point-in-time recovery
  • 99.98% uptime SLA, 4-week rolling history public

Privacy & data residency

  • Choose US, EU, or APAC as your data region
  • Data never leaves your chosen region
  • 30-day data export window after cancellation
  • DPA, SCCs, and DPIA templates on request

Monitoring & response

  • 24/7 SOC with automated anomaly detection
  • 15-minute mean time to detect, 45-minute MTTR
  • Quarterly third-party penetration testing
  • Public status page + customer breach notification within 24h

Audit & logging

  • Immutable audit logs on every read, write, share, export
  • Stream to your SIEM via webhook or S3
  • 1-year hot retention, 7-year cold archive
  • Tamper-evident with cryptographic signing
What happens to your data

The path of a single
customer record, end to end.

01

Ingest

Encrypted in transit (TLS 1.3) the moment it leaves your browser. Validated, sanitized, rate-limited at the edge.

TLS 1.3 · WAF · DDoS
02

Process

Workers run in isolated VPCs, no public network. Memory wiped between jobs. Secrets via short-lived IAM roles only.

Private VPC · IAM
03

Store

Encrypted at rest with per-tenant keys. Stored only in your chosen region. Backups encrypted with separate key hierarchy.

AES-256 · KMS · Per-tenant
04

Access

Every read passes RBAC + audit log. SSO-enforced sessions. Zero-trust internal — even our engineers can't see your data without an approved break-glass ticket.

SSO · RBAC · Zero trust
Infrastructure

Where your data lives.

We run on hardened AWS accounts in three geographic regions. You pick yours at signup and we never copy your data outside it — not for backups, not for analytics, not for ML training. Period.

Every primary database is multi-AZ with synchronous replicas. We snapshot hourly, retain point-in-time recovery for 30 days, and run quarterly disaster-recovery drills with documented RPO of 5 minutes and RTO of 1 hour.

Live region status
All systems normal
  • United States us-east-199.99%
  • European Union eu-west-199.98%
  • Asia Pacific ap-southeast-199.97%
Trust center

Independently verified, not just claimed.

Click any badge for the latest audit report, attestation letter, or DPA. Nothing here is on the honor system.

SOC 2
Type II · current

Audited annually by Prescient Assurance against the Trust Services Criteria (Security, Availability, Confidentiality). Latest report: November 2025.

ISO 27001
Certified · 2022

Information Security Management System certified by Schellman. Surveillance audits annually, full recertification every three years. Cert no. IS-887421.

GDPR
EU rep appointed

EU-based data residency, Standard Contractual Clauses on file, DPIA template available. EU representative: VeraSafe Ireland Ltd.

HIPAA
BAA available

Business Associate Agreements available on Enterprise plans. Administrative, physical, and technical safeguards aligned with 45 CFR §164.

PCI DSS
Level 1 · v4.0

We don't store card data — payments tokenize through Stripe. Manager.Social itself is Level 1 attested for the payment processing environments we touch.

CCPA
Compliant

California residents can request data access, deletion, and opt-out via in-app controls or privacy@manager.social. We do not sell personal information.

FAQ

Security FAQ.

In the AWS region you choose at signup — US (us-east-1), EU (eu-west-1), or APAC (ap-southeast-1). Your data, including backups and logs, never crosses that boundary. Region is locked at the workspace level and only changeable via a written request and a controlled migration.

By default, no one. Customer support agents see only what you've explicitly shared in a ticket. Engineers cannot access production data without an approved break-glass ticket signed by two security officers — every such access is logged, time-boxed, and reviewed weekly.

No. Our AI features either run on customer-isolated inference endpoints or call OpenAI/Anthropic with zero-data-retention agreements. We never use your content to train shared models. This is contractual, not a promise — it's in your DPA.

You get a 30-day window to export everything in standard formats (CSV, JSON, full database dump for Enterprise). After that, we delete your data within 90 days from primary storage and within 180 days from backups. You receive a signed Certificate of Destruction on request.

Yes — on the Enterprise plan. We support customer-managed keys via AWS KMS in your own AWS account. You can rotate, audit, or revoke at any time; revocation immediately renders your data unreadable to us.

We follow a documented incident response runbook with defined severity levels and customer notification SLAs. For any incident affecting customer data, you'll receive a direct email and in-app banner within 24 hours, followed by a public post-mortem within 14 days.

Yes. SAML 2.0 SSO with Okta, Azure AD, Google Workspace, JumpCloud, OneLogin, and any SAML-compliant IdP. SCIM 2.0 for automated user provisioning and deprovisioning. Both are included on Business and Enterprise plans, no upcharge.

Our Trust Center (linked above) hosts the live SOC 2, ISO 27001, and pen-test summaries. For deeper review we provide standard questionnaires (CAIQ, SIG Lite) and will meet with your team under NDA. Email security@manager.social to start.

Talk to us

Question we haven't
answered? Ask.

Our security team responds to every inbound — typically within one business day. For sensitive disclosures, use our PGP key (fingerprint below).