Skip to main content

Compliance reads as capability here.

Bryn's wedge is the record. Kill switches, retention controls, and audit exports are product features, not warning labels. This page is written for the people who sign off: your security lead, your data protection officer, your CFO.

The summary your security lead asks for first

S1 ⬩ Tenancy

Workspace isolation

Your signals, scores, and Plays live in your workspace.

S2 ⬩ Access

Least privilege, on the record

Access to customer workspaces is least-privilege and itself audit-logged, under the access and security provisions of the DPA.

S3 ⬩ Bounded writes

Writes only where a Play names

No unbounded API calls, no channels outside the Play definition. The action model is the security model.

Scope boundaries, stated plainly

P1 ⬩ Scope

Bryn watches where you point

The beacon, telemetry, and CRM scopes are explicit configuration. Nothing outside the configured scope is collected, and the scope itself is visible in the product.

P2 ⬩ No phone home

Your signal, no one else's model

What Bryn learns from your workspace stays in your workspace. The v0 learning substrate is your own audit log, nothing pooled.

P3 ⬩ Jurisdiction

US-only at launch, kill switch

Identification can be suspended by region, segment, or Play in one click. The audit log captures the suspend. Bryn waits. You decide when.

P4 ⬩ Erase

Account trails, erased on demand

The erase runs on demand, and the erase itself is logged as an erase. An auditable gap is better than a silent one.

The record is the product. Retention is under your control

Every signal, score, decision, and run is time-stamped, source-traced, and replayable. Export the log as CSV or JSON at any time. Erase on demand. Retention windows are configurable per workspace.

Workspace controls
  • retentionconfigurable per workspace
  • exportCSV / JSON, full fidelityany time
  • eraseon demand, logged as an eraseone click
  • timestampsliteral UTC, never relativealways
AICPA SOC for Service Organizations seal
Type 1Civic Auth
AICPA SOC for Service Organizations seal
Type 2Civic AuthCivic Hub

Civic Auth holds SOC 2 Type 1. Civic Auth and Civic Hub hold SOC 2 Type 2, each examined by an independent auditor under AICPA criteria for security, availability, and confidentiality. Civic Hub also holds Google CASA Tier 2. Civic's second Type 2 audit period is now underway and includes Bryn by Civic under the same controls and criteria. Reports are available on request, and each certification is detailed below.

The certifications behind the controls

Bryn runs inside Civic's controls. Every attestation below was examined by an independent auditor, and every report is available on request.

AICPA SOC for Service Organizations seal
SOC 2Type 2
SecurityAvailabilityConfidentiality
C1SOC 2 Type 2

Civic achieves SOC 2 Type 2 compliance

Demonstrating that our security controls are not only suitably designed but operate effectively over time.

Read moreShow less

Civic has achieved SOC 2 Type 2 compliance, building on our SOC 2 Type 1 attestation and confirming that our security controls operate effectively over time to protect client data and maintain the highest security standards across our company.

SOC 2 Type 2 compliance, established by the American Institute of Certified Public Accountants (AICPA), evaluates our security controls and practices over a defined period rather than at a single point in time. Where a Type 1 attestation confirms that controls are suitably designed as of a specific date, a Type 2 attestation confirms that those controls were both suitably designed and operating effectively throughout the examination period. It covers the same three critical trust service criteria: security, availability, and confidentiality.

The audit involved an independent examination of our internal controls, security policies, and operational procedures across the entire period under review. Auditors tested our data handling practices, access controls, system monitoring, and incident response capabilities, gathering evidence that each control performed consistently over time. This thorough review confirmed that our controls were suitably designed and operating effectively to meet the SOC 2 criteria, aligning with recognized security and compliance standards.

Our commitment extends beyond simply meeting audit requirements. Compliance and security criteria are baked into how we design, build, and operate everything we offer, acting as a continuous discipline rather than a point-in-time milestone. For the go-to-market teams who run on Civic, and the compliance and finance leaders accountable for every vendor they approve, that is the difference between a control that checks a box and one that fulfills the underlying criteria.

AICPA SOC for Service Organizations seal
SOC 2Type 1
SecurityAvailabilityConfidentiality
C2SOC 2 Type 1

Civic achieves SOC 2 Type 1 compliance

Proving our commitment to security, trust, and protecting sensitive data.

Read moreShow less

Civic has achieved SOC 2 Type 1 compliance, underscoring our commitment to protecting client data and maintaining the highest security standards across our company.

SOC 2 Type 1 compliance, established by the American Institute of Certified Public Accountants (AICPA), evaluates our security controls and practices at a specific point in time. This attestation confirms our controls are suitably designed to meet rigorous industry standards as of the audit date. It covers three critical trust service criteria: security, availability, and confidentiality.

The pre-audit process involved extensive evaluation of our internal controls, security policies, and operational procedures. Independent auditors examined our data handling practices, access controls, system monitoring, and incident response capabilities. This thorough review confirmed that our controls were suitably designed to meet the SOC 2 criteria, aligning with recognized security and compliance standards.

Our compliance extends beyond meeting audit requirements. We've integrated security considerations into every aspect of our business, from how we design and build our products to how we operate them for the go-to-market teams who depend on Civic. Security is a standing priority, not a one-time exercise.

Google CASA Tier 2 Certified
Google CASATier 2
OWASP ASVS Level 214 Security CategoriesNo High-Risk Vulnerabilities
C3Google CASA Tier 2

Civic passes Google CASA Tier 2 security assessment

Secure integrations start with secure code.

Read moreShow less

Civic passed Google's Cloud Application Security Assessment (CASA) Tier 2 certification. An authorized third-party lab tested our platform against key security requirements mandated by the App Defense Alliance's Tier 2 standard, which is based on OWASP ASVS v4.0, and found no high-risk vulnerabilities. The App Defense Alliance, led by Google, Meta, and Microsoft, administers this assessment.

CASA Tier 2 evaluates application security controls across 14 critical security categories. Independent assessors examined our API security, access controls, data handling practices, cryptographic implementations, and authentication flows. They mapped our code against common weakness enumerations with high exploit potential and verified compliance with OWASP ASVS Level 2 requirements.

Supply chain security has become central to enterprise risk management. Organizations now face requirements to verify the security posture of every vendor in their technology stack. CASA Tier 2 gives clients concrete evidence for stakeholder reviews and audit requirements — an official Letter of Validation (LoV) rather than self-certification.

For the assessment, our engineering and security teams enhanced secure coding practices, strengthened continuous security testing, and refined threat modeling processes. The lab conducted Dynamic Application Security Testing (DAST), reviewed our source code using Static Application Security Testing (SAST), and validated our defenses against the OWASP Top 10 and beyond.

Questions about our security practices?

If you are interested in learning more about our security practices or how our compliance supports your AI initiatives and regulatory requirements, we encourage you to reach out directly.

Paper your counsel can hold

The documents your legal and security teams ask for, every one published here and one click away.

D1 ⬩ Privacy

Privacy Policy

How Civic handles personal data across its products.

D2 ⬩ CSA

Customer Services Agreement

Civic's primary terms document, covering every product including Bryn.

D3 ⬩ Product terms

Customer Product Specific Terms

The product-specific terms that sit downstream of the CSA.

D4 ⬩ DPA

Data Processing Agreement

Processor terms for the signal scope you configure.

D5 ⬩ Sub-processors

Sub-processor list

Every downstream processor, by role.

Bring Compliance to the trial

The record starts when the trial does.