AuditMii
Security overview

A security-first approach

A transparent look at how we protect your account, data, and integrations as an early-stage platform building trust from day one.

No certifications claimed yet

We do not currently hold formal certifications such as SOC 2 or ISO 27001. These are on our roadmap as the company matures. Everything below describes controls we have implemented today.

Encryption everywhere

All traffic between your browser and Auditmii is encrypted with TLS. Application, database, and background-worker services run in isolated, access-controlled environments. Secrets and connected-integration credentials are encrypted at rest.

TLS in transit AES-256 at rest

Data protection & backups

We run automated, scheduled backups of workspace data with alerting if a backup fails. Export and deletion requests are handled through a dedicated workflow.

Read our privacy policy
In progress

Compliance roadmap

We are actively preparing for SOC 2 Type II and ISO 27001 as our company matures.

Stage 1: Foundational controls20% complete

Identity & access

Access to production systems is limited to the engineers who need it, and every sensitive action taken inside a workspace — invites, role changes, API key creation — is recorded in an audit log visible to workspace owners.

Scoped API keys
Token rotation

Security infrastructure log

Current status of controls we have implemented today.

ProtocolStatusCadenceStandard
TLS 1.3 in transitLiveActive monitoringAES-256
Encryption at restLiveActive monitoringAES-256
Scoped, revocable API keysLiveReal-timeWorkspace-scoped
Automated backupsLiveDailyAlerting enabled
SOC 2 Type IIPlannedRoadmapNot yet certified
ISO 27001PlannedRoadmapNot yet certified

Have a specific security question?

Our team is happy to walk through our practices, custom questionnaires, or DPAs. Email security@auditmii.com to report a vulnerability responsibly.