Trust
Security and data handling
You are going to ask these questions before you send us a document. Here are the answers, written down, so you do not have to chase them.
The Solden platform is in limited release and onboarding by conversation. The controls below describe how customer data is handled today. Where something is planned rather than in place, it says so.
Where your data lives
All customer data is stored and processed in the United States, in the Microsoft Azure East US 2 region. It is not replicated outside the United States, and we do not use offshore processing.
Document extraction does not leave our tenant
This is the answer to the question we get asked most. Document extraction runs on models deployed inside Solden's own Microsoft Azure tenant, under our existing enterprise agreement.
- Your documents are not sent to any third-party model provider.
- Your documents are never used to train models, ours or anyone else's.
- There is no additional subprocessor involved in extraction.
Document text is also excluded from application logging and error reporting. A document that reaches a crash report is the same disclosure by a different route, so it is handled as a data-flow rule rather than a matter of care.
Encryption
In transit: TLS 1.2 or higher, with HTTP Strict Transport Security enforced. At rest: AES-256, using platform-managed keys.
Access control
- Multi-factor authentication is required for all staff access to production systems.
- Access is granted by least privilege and reviewed when roles change.
- No shared accounts and no shared credentials.
- Production access is logged.
Audit logging
Authentication, record access, exports, permission changes and billing changes are written to an append-only audit log. Customers can query their own organisation's log. It is retained for one year.
Backup and recovery
Databases are backed up continuously with point-in-time restore. Recovery objectives are an RTO of 8 hours and an RPO of 1 hour.
Restores are tested, not assumed. The most recent successful restore test was 2026-09-22. We publish that date because a backup nobody has restored is a hypothesis.
Vulnerability management
- Dependencies are scanned automatically, and security patches are applied on a defined schedule.
- Secret scanning runs against every commit.
- Penetration testing: Not yet commissioned.
Incident response
We maintain a documented incident response process covering detection, containment, eradication and post-incident review. If a confirmed breach affects your data, we will notify you within 72 hours of confirming it, with what we know at the time rather than waiting for a complete picture.
Compliance posture
Controls are mapped to the SOC 2 Trust Services Criteria. No audit has been commissioned yet, and we do not hold a SOC 2 report.
We would rather tell you that than imply otherwise. If a SOC 2 report is a hard requirement for you today, say so early and we will tell you whether our timeline works for you.
Subprocessors
These are the third parties that handle data on our behalf today. We publish only what is actually in use.
| Subprocessor | Purpose | Data |
|---|---|---|
| Microsoft Azure | Hosting and infrastructure | Site delivery, server logs |
| Microsoft 365 | Business email | Correspondence with us |
| Plausible Analytics | Cookieless site analytics | Aggregate page views. No cookies, no personal data |
Added later, as each goes live
- Azure (database, storage) — At platform general release
- Clerk — Authentication, at platform general release
- Transactional email provider — At platform general release
- Error monitoring — At platform general release, with personal data scrubbed before send
- Stripe — If and when card payments are accepted
We do not use advertising trackers on this site. There is no Meta Pixel, and no tag manager that could introduce one.
Reporting a vulnerability
Email security@soldenhq.com. We will acknowledge within two business days. We will not pursue legal action against researchers who act in good faith, avoid privacy violations and data destruction, and give us reasonable time to fix the issue before disclosing it.
Our security.txt is published at the usual location.
Security questionnaires
Send them. We would rather answer a questionnaire early than discover a blocker late. If you need a completed SIG Lite or CAIQ, ask and we will tell you the turnaround honestly.
Contractual terms, including our data processing addendum, are published alongside our legal entity details. Ask us for them in the meantime.