Build secure applications with IT governance
Softr gives teams the security, access controls, and governance they need to build and run business apps with confidence.


Security as a default. Not an afterthought
Access to our Trust Center containing our SOC 2 Type II report, Security Policies and Penetration Testing results are available on request.
SOC Type II
99.9% Uptime
GDPR
Centralize governance
Control who can build, manage, and access sensitive data across your organization.
Workspaces & teams
Manage teams with dedicated workspaces and permissions.
Workspace roles
Control who can build, publish, manage settings, and access data.
Application audit logs
See who changed what and when across your applications.
Database audit logs
Track changes to tables, fields, and database structure.
Data security & protection
Protect your data, control who can access it, and manage authentication across your apps and workspace.
Data hosting & protection
Control where your data is hosted and how it’s protected across storage, transfer, and connected sources.
EU or US data residency
Host your data in the EU (Germany) or US.
Encryption in transit & at rest
Protect data both in transit with 256-bit TLS and at rest with encryption.
Protected files & credentials
Use temporary URLs for file access, while keeping integration credentials and API keys encrypted and off the frontend.
Proxied data queries
Query connected sources through Softr without copying the underlying data.
Authentication & access for your app users
Control what each user can see and do, down to the record level.
Sign-in options
Let users sign in with email and password, magic link, social login, or SSO.
Multi-factor authentication
Add another layer of verification with authenticator apps, SMS, or email.
Roles & permissions
Group users by role, team, or data, then control which pages, blocks, actions, and records they can access.
Data & network restrictions
Restrict which records users can access across the app, and limit app access by IP address.
Authentication & identity for your team
Connect Softr to your identity provider to centralize authentication and automate access across your workspace and apps.
Single sign-on (SSO)
Authenticate your team and app users through your identity provider with SAML 2.0 or OpenID Connect.
Identity provisioning
Automatically provision and deprovision users with SCIM.
Multi-factor authentication
Require an additional authentication factor for workspace access.
Workspace access controls
Control what workspace members can access and manage with roles.
Reliability
Built on AWS with high availability, redundancy, and 24/7 monitoring, Softr keeps the apps your business depends on running smoothly.
99.9% uptime
Redundant AWS infrastructure with 24/7 monitoring.
Automated backups
Regular backups and disaster recovery keep data recoverable.
Real-time status page
Live system health and incident updates you can subscribe to.
Scales with you
Handles growing users and data without performance drops.
Frequently asked questions
Is Softr SOC 2 compliant?
Where does Softr store customer data?
Is Softr GDPR compliant?
How does Softr control which users can see which data?
How do I verify app permissions are correct before I publish?
Can our database credentials or API keys be exposed to end users?
What authentication methods does Softr support, and on which plans?
Can we control who is allowed to sign up for an app?
Does the Vibe Coding block introduce a security risk?
If we connect an AI assistant over MCP, does that create a second way into our data?
Report a vulnerability, get rewarded
Our bug bounty program is open to independent researchers by invite. Responsible disclosures are reviewed, prioritized by severity, and rewarded.