[.blog-callout]
TL;DR
- Softr completed a SOC 2 Type II audit with a clean report and no noted exceptions.
- The audit checks five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.
- It covers Softr's full platform today, including the interface builder, Softr Databases, and Softr Workflows.
- All user data is stored and hosted in Europe (Germany), keeping Softr aligned with GDPR.
- Security lives in visual, verifiable controls like users and permissions, not in code you have to trust blindly. [.blog-callout]
Today, we're excited to announce another major step in our journey to become a highly available and secure platform with the completion of a SOC 2 Type II audit.

Build apps confidently on a secure foundation
The SOC 2 information security audit provides an objective external assessment and a report on the examination of Softr's security practices. It assures you that the apps you create with Softr adhere to the highest availability and security standards.
Let's dive in 👇
What is SOC 2 certification?
SOC 2 certification (System and Organization Controls Report) is awarded after an independent third-party auditor comprehensively audits a company's security practices. The evaluation is based on five Trust Services Criteria developed by the American Institute of Certified Public Accountants (AICPA).
- Security: ensuring information is shielded from unauthorized access and other vulnerabilities.
- Availability: maintaining consistent uptime and accessibility of services.
- Processing Integrity: ensuring systems operate as intended.
- Confidentiality: protecting confidential information by limiting access, use, and storage.
- Privacy: safeguarding personal information against unauthorized access.
Softr's SOC 2 Type II report did not have any noted exceptions and was therefore issued a "clean" audit by a certified independent vendor.
Why this matters more today than ever
Since this audit, the software landscape has changed. AI tools now let anyone generate an app from a prompt, but generated code is not automatically trustworthy. In a study of over 100 LLMs, 45% of AI-generated code samples surfaced security vulnerabilities. Our own CTO, Artur Mkrtchyan, has seen this firsthand:
"I had a friend who is actually an engineer and they built a custom admin panel in Lovable. One day I asked, 'How do you know who has access to what?' He was silent for a few minutes and said, 'Let me check the code.' After five minutes of checking, he was still not sure who has access to what." - Artur Mkrtchyan, CTO & Co-founder, Softr
That's the gap Softr is built to close. Permissions in Softr live in a visible settings panel, not buried in generated code you'd have to read line by line to trust.
"The Softr difference is that permissions live in a visible panel, not in generated code. Visual schemas make it simple to verify block-level visibility configurations in a visual editor rather than auditing a black box of generated code." - Artur Mkrtchyan, CTO & Co-founder, Softr

What this means for the apps you build
A SOC 2 report covers the platform: hosting, infrastructure, and internal practices. It doesn't automatically secure the specific app you build on top of it, so Softr also gives you the tools to control access at the app level.
When you hide an action button or apply a data restriction for a user group, Softr enforces that rule on the backend, not just by hiding it in the interface. That means a client logging into your portal can only ever reach their own records, whether or not the button is visible. Set this up through users and permissions, and review the practical patterns in our guide to setting up user groups or our broader guide to keeping app data secure.
All of this runs on top of the same audited infrastructure, whether your data lives in a native Softr Database or a connected source like Airtable or Google Sheets. And because all user data is stored and hosted in Europe (Germany), Softr's compliance posture stays aligned with GDPR as well.
Customers building on Softr already rely on this for genuinely sensitive, multi-tenant use cases:
"It allows us to have a secure customer portal for each customer that is managed centrally. I appreciate its functionality in sending notifications, inviting users, and using magic links and other secure features. I also love the ability to control access globally, which is really important for data security and privacy." - Natalie S., Director of Operations, G2 review
Keep building on a platform you can trust
A clean SOC 2 Type II report doesn't change how you build with Softr day to day, but it means the foundation underneath every app, from a client portal to an internal tool, has been independently verified. Pair that with visual, backend-enforced permissions, and you get an app that's secure by default instead of secure by accident.
If you're setting up a new portal or internal tool, start with users and permissions before you build a single page. Getting that right from day one is what makes the rest of the app trustworthy.
Frequently asked questions
- What is SOC 2 Type II certification?
SOC 2 Type II is an independent audit that checks whether a company's security controls actually work over time, not just on paper. An outside auditor reviews the company's practices against five Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy) across several months, rather than a single point-in-time snapshot. A "clean" report, like the one Softr received, means the auditor found no exceptions.
- Does Softr's SOC 2 certification cover the whole platform, including Databases and Workflows?
Yes. The audit covers Softr's infrastructure and practices as a whole, which today spans the interface builder, Softr Databases, and Softr Workflows. Whether you're storing records in a native Softr Database or connecting an external data source, the same security foundation applies.
- Where is Softr's user data hosted?
All Softr user data is stored and hosted in Europe, specifically Germany. This keeps data handling aligned with GDPR and gives European and international teams a clear answer when clients or auditors ask where their information lives.
- How does SOC 2 compliance affect the apps I build with Softr?
It means the foundation under your app, hosting, authentication, and data storage, has been independently verified. On top of that, you still control who sees what inside your app using users and permissions: user groups, data restrictions, and page or block-level visibility rules. Those settings are enforced on the backend, not just hidden in the interface, so a client logging into your portal can only ever reach their own records.
- Does SOC 2 certification mean my Softr app is automatically secure?
It means the platform you're building on has been independently audited, but you still need to configure permissions correctly for your specific app. Softr makes that part visual instead of hidden in generated code: you set up user groups and data restrictions through a settings panel, so you can see and verify exactly who has access to what, rather than trusting an AI-written access check you can't easily audit.



