A security-first approach
A transparent look at how we protect your account, data, and integrations as an early-stage platform building trust from day one.
No certifications claimed yet
We do not currently hold formal certifications such as SOC 2 or ISO 27001. These are on our roadmap as the company matures. Everything below describes controls we have implemented today.
Encryption everywhere
All traffic between your browser and Auditmii is encrypted with TLS. Application, database, and background-worker services run in isolated, access-controlled environments. Secrets and connected-integration credentials are encrypted at rest.
Data protection & backups
We run automated, scheduled backups of workspace data with alerting if a backup fails. Export and deletion requests are handled through a dedicated workflow.
Read our privacy policyCompliance roadmap
We are actively preparing for SOC 2 Type II and ISO 27001 as our company matures.
Identity & access
Access to production systems is limited to the engineers who need it, and every sensitive action taken inside a workspace — invites, role changes, API key creation — is recorded in an audit log visible to workspace owners.
Security infrastructure log
Current status of controls we have implemented today.
| Protocol | Status | Cadence | Standard |
|---|---|---|---|
| TLS 1.3 in transit | Live | Active monitoring | AES-256 |
| Encryption at rest | Live | Active monitoring | AES-256 |
| Scoped, revocable API keys | Live | Real-time | Workspace-scoped |
| Automated backups | Live | Daily | Alerting enabled |
| SOC 2 Type II | Planned | Roadmap | Not yet certified |
| ISO 27001 | Planned | Roadmap | Not yet certified |
Have a specific security question?
Our team is happy to walk through our practices, custom questionnaires, or DPAs. Email security@auditmii.com to report a vulnerability responsibly.

