generated: '2026-08-06' method: searched probe: true source: https://www.asknicely.com/security url: https://www.asknicely.com/security description: >- AskNicely publishes a single public security page rather than a dedicated trust centre or trust portal. It names the compliance programme AskNicely itself holds (SOC 2, annual penetration testing, CSA CAIQ registry entry) separately from the certifications inherited from its AWS hosting (ISO 27001, PCI). certifications: - SOC 2 - ISO 27001 - PCI DSS - GDPR - CSA STAR (CAIQ) - New Zealand Privacy Act certification_detail: - name: SOC 2 held_by: AskNicely detail: AskNicely states it is SOC-2 compliant and maintains compliance through an annual independent audit. - name: ISO 27001 held_by: AWS (hosting provider) detail: Inherited from the AWS datacenters AskNicely runs on; not an AskNicely certification. - name: PCI DSS held_by: AWS (hosting provider) detail: Inherited from the AWS datacenters AskNicely runs on; not an AskNicely certification. - name: CSA STAR (CAIQ) held_by: AskNicely detail: AskNicely maintains a public entry in the Cloud Security Alliance registry. - name: GDPR held_by: AskNicely detail: GDPR compliance documented; a data processing addendum is available. - name: New Zealand Privacy Act held_by: AskNicely detail: Primary jurisdiction for AskNicely, headquartered in Auckland, New Zealand. practices: penetration_testing: Annual penetration testing of web and mobile applications. third_party_scans: Third-party security scans and audits conducted regularly. encryption_in_transit: TLS with forward secrecy; HSTS enabled; states an "A" rating on Qualys SSL Labs. encryption_at_rest: RDS encryption for the Australia and Europe regions and new US plans. backups: Automated backups with 14-day point-in-time recovery. monitoring: Amazon Inspector (vulnerability scanning), GuardDuty (intrusion detection), Macie (data leak scanning). hosting_regions: [AWS Oregon (US), AWS Sydney (AU), AWS Frankfurt (EU)] gaps: - No published vulnerability-disclosure or responsible-disclosure policy. - No bug bounty programme. - No /.well-known/security.txt on any AskNicely host. - No dedicated security contact address published on the security page. evidence: - source: https://www.asknicely.com/security http_status: 200 keywords: [soc 2, iso 27001, pci, gdpr, cloud security alliance, penetration testing]