generated: '2026-08-13' method: searched probe: true url: https://www.commonroom.io/security/ title: Security & Trust note: >- probe-security-programs.py recorded trust=none because it looks for a dedicated trust. / security. subdomain first — neither resolves for commonroom.io (DNS failure, HTTP 000). The trust surface is a first-party page on the marketing site instead, and it names certifications explicitly, so it is recorded here as a searched hit with the fetched evidence. probes: - url: https://trust.commonroom.io/ status: 000 note: DNS does not resolve - url: https://security.commonroom.io/ status: 000 note: DNS does not resolve - url: https://www.commonroom.io/compliance/ status: 404 - url: https://www.commonroom.io/security/ status: 200 note: The real trust surface certifications: - SOC 2 Type 2 regulations: - GDPR - CCPA claims: - area: Data Security statement: Data encryption in transit and at rest - area: Compliance statement: Right-to-be-forgotten, GDPR, SOC, etc. - area: Authentication statement: Fine-grained auth and permission control - area: Reliability statement: 99.9% uptime. Service-level agreement with 24/7 uptime monitoring. - area: Independent assurance statement: >- "We work with external partners to independently audit our security architecture and controls. We engage regularly with a penetration testing firm to provide independent assurance that we stay updated with security best practices." - area: Identity statement: >- "We support single sign-on and role-based access control, as well as SAML and SCIM via multiple identity providers, such as Okta, Microsoft Azure Active Directory, and more." - area: Third-party data statement: >- "All integrations use official APIs and conform to the terms of service of third-party providers." soc2_statement: >- "SOC Type 2 — Our SOC report demonstrates that we understand the necessary security procedures to safely handle customer data and that we've upheld these standards." documents: - name: Subscription services agreement format: PDF - name: Data processing addendum format: PDF - name: Privacy policy url: https://www.commonroom.io/privacy-policy/ - name: Terms of Use url: https://www.commonroom.io/terms-of-use/ programmatic_controls: - name: Right to be forgotten api: 'DELETE /user/{email}' spec: openapi/common-room-right-to-be-forgotten-api-openapi.yml note: >- "We adhere to GDPR and CCPA regulations and provide a programmatic integration to remove all personally identifiable information." - name: SCIM 2.0 provisioning api: https://api.commonroom.io/scim/v2 spec: openapi/common-room-scim-api-openapi.yml - name: Audit log streaming docs: https://www.commonroom.io/docs/using-common-room/streaming-audit-logs-to-your-siem/ note: >- Continuously streams security audit events — sign-ins, role changes, seat changes and API token activity — to a customer-owned S3 bucket. gaps: - No public trust portal (Vanta/Drata/SafeBase style) with downloadable evidence - No named ISO 27001, PCI DSS, HIPAA or FedRAMP certification - SOC 2 report is described but not requestable from a self-serve link on the page - No public status page despite the published 99.9% uptime target evidence: - source: https://www.commonroom.io/security/ http_status: 200 fetched: '2026-08-13' keywords: [soc type 2, gdpr, ccpa, penetration testing, encryption, sso, rbac, saml, scim, uptime, service-level agreement]