ShipSilently
Pricing Docs Compare Changelog
Academy A chapter-by-chapter guide to feature flags Blog Field notes on rollouts, edge, and engineering culture Tools Free calculators & utilities (A/B sizing & more) Arcade Free browser games for people who ship FAQ Common questions, answered honestly
Sign In Start Free

Security

Last reviewed: July 2026

ShipSilently is an early-stage company. We want to be straightforward about where we are: we have not completed a SOC 2 examination, and we do not claim SOC 2 certification or display the AICPA SOC service mark, which is reserved for organizations with a completed report from a licensed CPA firm. What follows is an honest description of our internal security practices today and our plan to formalize them.

Where we are today

We've run an internal self-assessment of our infrastructure and application against the AICPA's SOC 2 Trust Services Criteria (security, availability, confidentiality) and written internal policies covering the areas an auditor would eventually review. This is a self-assessment performed by our own team, not an independent audit — we're publishing it here because we think partial transparency beats a badge nobody can verify.

Practices in place

  • Encryption in transit and at rest: TLS 1.2+ for all traffic; data at rest encrypted via our infrastructure provider (Cloudflare D1/KV).
  • Access control: Role-based access within organizations; production access limited to a small number of engineers; authentication via WorkOS for the dashboard.
  • Change management: All production changes go through pull request review and CI before deploy.
  • Vendor review: We track and evaluate the subprocessors we rely on (Cloudflare, WorkOS, Stripe, and others) before adding them to our stack.
  • Incident response: We maintain an internal incident response process with defined severities and a customer-notification commitment for any incident involving personal data.
  • Ongoing internal review: We re-run our internal control self-assessment periodically and track findings until resolved.

Where we're headed

Our plan is to formalize this internal program into a real, third-party-audited SOC 2 report as the company grows — starting with a Type I (point-in-time) examination and moving to Type II (examination over an observation period) once we've engaged a licensed CPA firm. We don't have a committed date to share yet, and we won't claim "audit in progress" until an auditor is actually engaged. If SOC 2 status matters for your procurement process, reach out — we're happy to walk through our current controls directly and share updates as our program matures.

Reporting a vulnerability

If you believe you've found a security issue in ShipSilently, please email us at hello@shipsilently.com. We take reports seriously and will respond promptly.

ShipSilently

The stealthy, reliable feature flag management system built for teams who want to test in production without the risk.

Node SDK React SDK Go SDK
YouTube

Product

  • Feature Flags
  • Pricing
  • Compare tools
  • LaunchDarkly alternative
  • LaunchDarkly guides
  • Migrate
  • Roadmap

Resources

  • Docs
  • Academy
  • Blog
  • Changelog
  • FAQ

Tools & Games

  • Flag Cost Calculator
  • A/B Test Calculator
  • All free tools
  • Zombie Flag
  • Flag Shift
  • Arcade

Company

  • Careers
  • Status
  • Security
  • Privacy Policy
  • Terms of Service
  • hello@shipsilently.com

© 2026 ShipSilently Inc. All rights reserved.

Blog Privacy Policy Terms of Service

We use cookies to improve your experience. By continuing, you agree to our Privacy Policy.