Security
Learn how we protect our platform and customer data through encryption, access controls, monitoring, secure
development practices, and ongoing testing.
SOCRadar Trust Center

Message from the CEO:
At SOCRadar, trust is not a statement — it is a responsibility.
Our customers rely on us to deliver timely, accurate threat intelligence while protecting the data entrusted to us. That responsibility drives every decision we make, from how we design our platform to how we train our people and engage with independent auditors.
Security, privacy, and compliance are not one-time achievements. They are continuous commitments. Through internationally recognized certifications, transparent practices, and rigorous internal controls, we work every day to earn and maintain your trust.
Thank you for choosing SOCRadar as your partner in navigating the evolving threat landscape.
— CEO, SOCRadar
Trust is the foundation of how we build, operate, and secure SOCRadar. This Trust Center provides a clear view into
our security, privacy, compliance, and reliability practices.
These certifications and attestations reflect independent assurance of our security and compliance controls.
At SOCRadar, trust is not a statement — it is a responsibility.
Our customers rely on us to deliver timely, accurate threat intelligence while protecting the data entrusted to us.
That responsibility drives every decision we make, from how we design our platform to how we train our people and
engage with independent auditors.Security, privacy, and compliance are not one-time achievements. They are continuous commitments. Through
internationally recognized certifications, transparent practices, and rigorous internal controls, we work every day
to earn and maintain your trust.Thank you for choosing SOCRadar as your partner in navigating the evolving threat landscape.
Learn how we protect our platform and customer data through encryption, access controls, monitoring, secure
development practices, and ongoing testing.
Understand what data we process, how we use it, and how we support applicable data subject rights. We limit access
by role and follow least-privilege principles.
Review our certifications and attestations, including ISO/IEC 27001, SOC 2 Type I/II, and CSA STAR Level 1.
See how we plan for continuity, respond to incidents, and maintain resilient operations designed to support service
availability.
SOCRadar operates a risk-based information security program designed to protect the confidentiality, integrity, and
availability of customer data.
To report a security concern or vulnerability, contact:
[email protected]
SOCRadar is committed to responsible processing of personal data and transparency in how data is handled across our
services and operations.
We embed privacy principles into product development and operational processes, including data minimization, access
restriction by role, and security controls that help protect personal data.
Depending on the service and customer relationship, SOCRadar may process limited personal data such as:
Access to customer and personal data is restricted by role and aligned with least-privilege principles:
| Role | Accessible Data |
|---|---|
| Marketing | Name, Surname, Email, Company Name, Country |
| Analyst / Development | Name, Surname, Email, Company Name, Country, IP, Threat Intel Findings |
| Customer Success | Name, Surname, Email, Company Name, Country, Phone Number, Threat Intel Findings |
| Sales | Name, Surname, Email, Company Name, Country, Phone Number, Threat Intel Findings, Finance Information |
| Finance | Name, Surname, Email, Company Name, Country, Finance Information |
Where applicable, SOCRadar supports data subject rights such as access, rectification, deletion, restriction, and
objection. Requests can be submitted via:
[email protected]
For privacy inquiries, contact:
[email protected]
SOCRadar maintains a compliance program aligned with recognized standards and validated through independent
assessments.
Our controls are assessed against internationally recognized frameworks to provide customers with confidence in our
security and compliance posture.
SOCRadar maintains documented policies and procedures across areas such as risk management, access management,
encryption, vulnerability management, secure development, vendor management, and incident response.
For questions regarding compliance or due diligence, contact:
[email protected]
SOCRadar maintains resilience practices designed to support service availability and respond effectively to
disruptions and security incidents.
Our business continuity practices are designed to help maintain critical operations during unexpected events through
documented planning, operational readiness, and periodic review.
If a security incident occurs, we follow defined processes to investigate, contain, and remediate. Customers are
notified in accordance with contractual and regulatory obligations.
For real-time updates on service availability, visit our status page:
{{STATUS_URL}}
If you need assistance, contact:
[email protected]
SOCRadar encourages responsible vulnerability disclosure and values collaboration with the security research
community.
Please include:
Email our security team at:
[email protected]
[email protected] ([email protected])
[email protected] ([email protected])
[email protected] ([email protected])
SOCRadar uses industry-standard encryption to protect data in transit and at rest, supported by controlled key
management practices.
We protect data transmitted between clients, services, and external dependencies using modern TLS configurations.
This helps reduce the risk of interception or tampering while data moves across networks.
Where appropriate, we encrypt sensitive data stored in databases, backups, and other storage layers to help prevent
unauthorized access in the event of exposure.
Encryption is supported by key management practices designed to control how cryptographic keys are created, stored,
used, rotated, and retired.
For due diligence inquiries about encryption practices, contact:
[email protected]
SOCRadar restricts access to systems and data using least-privilege principles, role-based access control (RBAC),
and safeguards for privileged operations.
Access is provisioned based on job responsibilities and limited to what is required to perform assigned duties.
Access requests, changes, and removals follow defined workflows.
Authentication controls are implemented to reduce unauthorized access risks and strengthen account security.
Privileged access is restricted and monitored. Administrative access is protected by layered security controls and
logging.
SOCRadar applies segregation-of-duties practices to reduce the risk of unauthorized or unreviewed changes.
For access-control due diligence questions, contact:
[email protected]
SOCRadar identifies, prioritizes, and remediates vulnerabilities using a risk-based approach across infrastructure,
applications, and supporting components.
We prioritize remediation based on severity and business risk. The table below provides high-level target timelines.
Actual timelines may vary based on impact, exploitability, affected scope, and compensating controls.
| Severity | Typical Examples | Target Remediation |
|---|---|---|
| Critical | Actively exploitable or high-impact exposure | As soon as possible (accelerated) |
| High | Significant risk; plausible exploitation | Prioritized, risk-based timeline |
| Medium | Moderate impact; often requires preconditions | Scheduled remediation |
| Low | Low impact or informational findings | As resources permit / backlog |
If you believe you have found a vulnerability, please report it privately through our Responsible Disclosure page.
For vulnerability management and due diligence questions, contact:
[email protected]
SOCRadar assesses and manages third-party vendors to reduce supply-chain risk and help ensure appropriate security
and privacy controls are in place.
Before onboarding and during ongoing relationships, we apply a risk-based approach that considers the nature of the
service, data sensitivity, and operational criticality.
Vendor access to systems and data is limited to what is necessary to deliver services. Where applicable, we use
controls such as least privilege, segmentation, and logging.
SOCRadar does not currently publish a public subprocessors list on this page. If you require subprocessor details
for procurement or compliance, please contact us.
For vendor management due diligence requests, contact:
[email protected]
Quick answers to common security, privacy, compliance, and reliability questions for customers and procurement
teams.
Yes. SOCRadar uses industry-standard encryption practices to protect data in transit (TLS) and applies encryption
at rest for sensitive data where appropriate. See Encryption & Key Management.
SOCRadar uses MFA for privileged access and key systems where applicable, alongside RBAC and periodic access
reviews. See Access Control.
We use a risk-based vulnerability management program including scanning, testing, prioritization, remediation,
and verification where applicable. See Vulnerability Management.
Yes. We encourage responsible disclosure and provide a dedicated reporting channel. See
Responsible Disclosure.
SOCRadar maintains ISO/IEC 27001, SOC 2 Type I, SOC 2 Type II, and CSA STAR Level 1. See
Compliance.
This Trust Center is public. If you require detailed reports for procurement due diligence, please contact
[email protected].
We apply least-privilege and RBAC. Access is restricted by role and reviewed periodically. See
Privacy and Access Control.
Privacy inquiries and applicable data subject requests can be submitted to
[email protected].
Yes. SOCRadar maintains incident response practices to investigate, contain, remediate, and notify customers when
required by contract or regulation. See Reliability.
Visit our status page: {{STATUS_URL}}.
PROTECTION OF PERSONAL DATA COOKIE POLICY FOR THE INTERNET SITE
Protecting your personal data is one of the core principles of our organization, SOCRadar, which operates the internet site (www.socradar.com). This Cookie Usage Policy (“Policy”) explains the types of cookies used and the conditions under which they are used to all website visitors and users.
Cookies are small text files stored on your computer or mobile device by the websites you visit.
Cookies are commonly used to provide you with a personalized experience while using a website, enhance the services offered, and improve your overall browsing experience, contributing to ease of use while navigating a website. If you prefer not to use cookies, you can delete or block them through your browser settings. However, please be aware that this may affect your usage of our website. Unless you change your cookie settings in your browser, we will assume that you accept the use of cookies on this site.
1. WHAT KIND OF DATA IS PROCESSED IN COOKIES?
Cookies on websites collect data related to your browsing and usage preferences on the device you use to visit the site, depending on their type. This data includes information about the pages you access, the services and products you explore, your preferred language choice, and other preferences.
2. WHAT ARE COOKIES AND WHAT ARE THEIR PURPOSES?
Cookies are small text files stored on your device or web server by the websites you visit through your browsers. These small text files, containing your preferred language and other settings, help us remember your preferences on your next visit and assist us in making improvements to our services to enhance your experience on the site. This way, you can have a better and more personalized user experience on your next visit.
The main purposes of using cookies on our Internet Site are as follows:
3. TYPES OF COOKIES USED ON OUR INTERNET SITE 3.1. Session Cookies
Session cookies ensure the smooth operation of the internet site during your visit. They are used for purposes such as ensuring the security and continuity of our sites and your visits. Session cookies are temporary cookies and are deleted when you close your browser; they are not permanent.
3.2. Persistent Cookies
These cookies are used to remember your preferences and are stored on your device through browsers. Persistent cookies remain stored on your device even after you close your browser or restart your computer. These cookies are stored in your browser’s subfolders until deleted from your browser’s settings. Some types of persistent cookies can be used to provide personalized recommendations based on your usage purposes.
With persistent cookies, when you revisit our website with the same device, the website checks if a cookie created by our website exists on your device. If so, it is understood that you have visited the site before, and the content to be presented to you is determined accordingly, offering you a better service.
3.3. Mandatory/Technical Cookies
Mandatory cookies are essential for the proper functioning of the visited internet site. The purpose of these cookies is to provide necessary services by ensuring the operation of the site. For example, they allow access to secure sections of the internet site, use of its features, and navigation.
3.4. Analytical Cookies
These cookies gather information about how the website is used, the frequency and number of visits, and show how visitors navigate to the site. The purpose of using these cookies is to improve the operation of the site, increase its performance, and determine general trend directions. They do not contain data that can identify visitors. For example, they show the number of error messages displayed or the most visited pages.
3.5. Functional Cookies
Functional cookies remember the choices made by visitors within the site and recall them during the next visit. The purpose of these cookies is to provide ease of use to visitors. For example, they prevent the need to re-enter the user’s password on each page visited by the site user.
3.6. Targeting/Advertising Cookies
They measure the effectiveness of advertisements shown to visitors and calculate how many times ads are displayed. The purpose of these cookies is to present personalized advertisements to visitors based on their interests.
Similarly, they determine the specific interests of visitors’ navigation and present appropriate content. For example, they prevent the same advertisement from being shown again to the visitor in a short period.
4. HOW TO MANAGE COOKIE PREFERENCES?
To change your preferences regarding the use of cookies, block or delete cookies, you only need to change your browser settings.
Many browsers offer options to accept or reject cookies, only accept certain types of cookies, or receive notifications from the browser when a website requests to store cookies on your device.
Also, it is possible to delete previously saved cookies from your browser.
If you disable or reject cookies, you may need to manually adjust some preferences, and certain features and services on the website may not work properly as we will not be able to recognize and associate with your account. You can change your browser settings by clicking on the relevant link from the table below.
5. EFFECTIVE DATE OF THE INTERNET SITE PRIVACY POLICY
The Internet Site Privacy Policy is dated The effective date of the Policy will be updated if the entire Policy or specific sections are renewed. The Privacy Policy is published on the Organization’s website (www.socradar.com) and made accessible to relevant individuals upon request.
SOCRadar
Address: 651 N Broad St, Suite 205 Middletown, DE 19709 USA
Phone: +1 (571) 249-4598
Email: [email protected]
Website: www.socradar.com