Security
Last reviewed: July 2026
ShipSilently is an early-stage company. We want to be straightforward about where we are: we have not completed a SOC 2 examination, and we do not claim SOC 2 certification or display the AICPA SOC service mark, which is reserved for organizations with a completed report from a licensed CPA firm. What follows is an honest description of our internal security practices today and our plan to formalize them.
Where we are today
We've run an internal self-assessment of our infrastructure and application against the AICPA's SOC 2 Trust Services Criteria (security, availability, confidentiality) and written internal policies covering the areas an auditor would eventually review. This is a self-assessment performed by our own team, not an independent audit — we're publishing it here because we think partial transparency beats a badge nobody can verify.
Practices in place
- Encryption in transit and at rest: TLS 1.2+ for all traffic; data at rest encrypted via our infrastructure provider (Cloudflare D1/KV).
- Access control: Role-based access within organizations; production access limited to a small number of engineers; authentication via WorkOS for the dashboard.
- Change management: All production changes go through pull request review and CI before deploy.
- Vendor review: We track and evaluate the subprocessors we rely on (Cloudflare, WorkOS, Stripe, and others) before adding them to our stack.
- Incident response: We maintain an internal incident response process with defined severities and a customer-notification commitment for any incident involving personal data.
- Ongoing internal review: We re-run our internal control self-assessment periodically and track findings until resolved.
Where we're headed
Our plan is to formalize this internal program into a real, third-party-audited SOC 2 report as the company grows — starting with a Type I (point-in-time) examination and moving to Type II (examination over an observation period) once we've engaged a licensed CPA firm. We don't have a committed date to share yet, and we won't claim "audit in progress" until an auditor is actually engaged. If SOC 2 status matters for your procurement process, reach out — we're happy to walk through our current controls directly and share updates as our program matures.
Reporting a vulnerability
If you believe you've found a security issue in ShipSilently, please email us at hello@shipsilently.com. We take reports seriously and will respond promptly.