Skip to content
super.AI

Compliance

Your data security is our priority.

We are SOC 2 Type II audited

super.AI is built from the ground up with security in mind. An independent CPA firm audits us annually against the SOC 2 Security criteria, and our current SOC 2 Type II report covers the observation period ending January 2026. The report and our security documentation are held in our Security documents (Vanta). The SOC 2 Type II report, Trust Center access and the contractual security commitments in the Enterprise Agreement apply to Enterprise customers only, and are available to organisations evaluating the Enterprise plan. Self-service and Growth plans are not covered by our SOC 2 commitment and do not receive the report; what applies to them is the Self-Service Terms of Service and the published policies below.

SOC 2

System and Organization Controls (SOC) reports serve as independent third-party examination documents that showcase an organization's adherence to essential compliance controls and objectives.

SOC 2 reports are grounded in the Trust Services Criteria (TSC) established by the American Institute of Certified Public Accountants (AICPA) Auditing Standards Board. The primary goal of these reports is to assess an organization's information systems in relation to security, availability, processing integrity, confidentiality, and privacy.

To ensure compliance, super.AI undergoes stringent independent third-party SOC 2 audits performed by a reputable certified public accountant (CPA) firm on a regular basis. This audit firm examines whether super.AI's compliance controls are not only suitably designed, but also operational on a specific date and effective over a designated time period.

Enterprise customers, and organisations evaluating the Enterprise plan, can read the SOC 2 Type II report and our security documentation by emailing support@super.ai and we will grant Trust Center access.

AICPA SOC badge

GDPR

super.AI adheres to the General Data Protection Regulation (GDPR). The GDPR expands the privacy rights granted to European individuals and requires certain companies that process the personal data of European individuals to comply with a new set of regulations. In particular, the GDPR may apply to companies that process the personal data of European individuals and have a presence in the EU (e.g. offices or establishments) and to companies that do not have any presence in the EU but target the European market (e.g. by offering goods or services to the European market) or monitor the behavior of European individuals. We're here to help our customers in their efforts to comply with the GDPR.

Learn more in our Privacy Policy. The Super.AI Enterprise Agreement is the contract for enterprise customers and applies where an Order or Statement of Work incorporates it. If you have a separately negotiated agreement with us, that agreement governs. Self-service accounts are governed by the Self-Service Terms of Service, whose section 16 is the data processing agreement.

Blue circular badge with twelve yellow stars and text 'EU GDPR' in the center, surrounded by 'COMPLIANT' repeated three times.