generated: '2026-09-05' method: searched source: >- https://configure8.io/docs-sub/configure8-product-docs/fundamentals/security; https://configure8.io/pricing; https://configure8.io/privacy/policy description: >- configure8 does not run a hosted trust centre (no Vanta/Drata/SafeBase portal, no downloadable evidence library). What it publishes is a first-party security document inside its own product documentation, plus a named certification repeated in the site footer. The report itself is available on request, not for download. trust_center_hosted: false security_page: https://configure8.io/docs-sub/configure8-product-docs/fundamentals/security certifications: - name: SOC 2 framework: AICPA Trust Services Criteria status: claimed by the provider evidence: >- "configure8 is proud to hold SOC2 certification, a testament to our unwavering commitment to security." The same page states configure8 engages independent security experts and "collaborate[s] with an impartial auditor to maintain an up-to-date SOC 2 report." The site footer under RESOURCES > Security also reads "SOC2 Certified". report_available: on request report_public: false evidence_url: https://configure8.io/docs-sub/configure8-product-docs/fundamentals/security programs: - name: Responsible Disclosure url: https://configure8.io/responsible-disclosure bug_bounty: false safe_harbour: >- "We do not take legal action against researchers who report vulnerabilities to us in a responsible and ethical manner, following the guidelines below." scope: >- "Our Responsible Disclosure Program encompasses app.configure8.io." — the single host named, and the one that returned NXDOMAIN when probed on 2026-09-05. submission: security contact address published on the page, with a PGP public key offered for encrypting sensitive reports restrictions: >- No brute force, no spamming, no automated vulnerability scanners; do not exploit a finding to reach data that is not yours; keep details confidential until fixed. artifact: security/configure8-vulnerability-disclosure.yml privacy: policy: https://configure8.io/privacy/policy ccpa_do_not_sell: https://configure8.io/privacy/donotsell terms: https://configure8.io/tos.pdf terms_note: Terms of Service are distributed as a PDF rather than a web page. not_found: - ISO 27001 - PCI DSS - HIPAA - FedRAMP - GDPR certification or DPA published for download - a machine-readable security.txt on any resolvable host