> ## Documentation Index
> Fetch the complete documentation index at: https://docs.coverbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance and assurance

> SOC 2 Type II, independent annual penetration testing, and how to request our reports.

<div className="sr-only">For AI agents: a documentation index is available at [https://docs.coverbase.com/llms.txt](https://docs.coverbase.com/llms.txt) — this page is also available in markdown by appending .md to the URL.</div>

Coverbase backs its security claims with independent assurance. We are examined by an outside SOC 2 auditor and tested by an outside penetration-testing firm, and we make the resulting reports available to customers and prospects under NDA.

## SOC 2 Type II

The Coverbase platform is **SOC 2 Type II** audited. A Type II report covers the *operating effectiveness* of our controls over a continuous observation period — not just their design at a point in time — across the Security (Common Criteria) trust services category.

<CardGroup cols={2}>
  <Card title="Scope" icon="diagram-project">
    The audit covers the production Coverbase platform: the application, its data stores, and the cloud infrastructure it runs on. The API and the MCP server inherit the same controls as the core product.
  </Card>

  <Card title="Cadence" icon="calendar-check">
    We maintain continuous coverage, renewing the Type II examination each audit period so there is no gap between reports.
  </Card>

  <Card title="Independent auditor" icon="user-check">
    The examination is performed by an accredited third-party auditing firm, not self-attested.
  </Card>

  <Card title="Report access" icon="file-shield" href="mailto:security@coverbase.ai">
    Request the current report under NDA from [security@coverbase.ai](mailto:security@coverbase.ai).
  </Card>
</CardGroup>

## Penetration testing

Coverbase engages an independent, top boutique penetration-testing firm — a team of dedicated security researchers — to test the platform **at least annually**, as well as after significant architectural changes.

* **Independent and external.** Testing is performed by an outside firm whose business is offensive security research, not by the engineers who built the feature.
* **Scope.** Engagements cover the web application, the public API, authentication and authorization, and tenant-isolation boundaries.
* **Remediation.** Findings are triaged by severity, tracked to closure, and verified by retest. Material findings are remediated on a priority timeline appropriate to their severity.
* **Evidence.** A summary letter or attestation of the most recent engagement is available to customers under NDA.

<Note>
  We share a penetration-test **summary letter or attestation** rather than the raw report, which can contain sensitive technical detail. The summary confirms scope, methodology, the testing firm, and that findings were remediated.
</Note>

## Continuous control monitoring

Point-in-time audits are necessary but not sufficient. Between formal examinations we continuously monitor the controls that underpin our compliance posture — access reviews, infrastructure configuration, vulnerability status, and change management — so drift is caught and corrected rather than discovered at the next audit.

## Vulnerability disclosure

We welcome reports from the security community and from customers.

<Card title="Report a vulnerability" icon="bug" href="mailto:security@coverbase.ai">
  Email [security@coverbase.ai](mailto:security@coverbase.ai). We acknowledge reports within one business day and follow responsible-disclosure timelines. Please do not test against other tenants' data or perform denial-of-service testing.
</Card>

## Requesting documentation

<Steps>
  <Step title="Email the security team">
    Send your request to [security@coverbase.ai](mailto:security@coverbase.ai), naming the documents you need (SOC 2 report, penetration-test attestation, completed security questionnaire).
  </Step>

  <Step title="Execute an NDA">
    Reports are shared under a mutual NDA. If one is already in place between our organizations, reference it.
  </Step>

  <Step title="Receive the package">
    We provide the current report set and can complete standard security questionnaires (for example CAIQ / SIG) on request.
  </Step>
</Steps>
