generated: '2026-07-18' method: searched source: https://docs.decube.io/security-and-infrastructure/security docs: https://www.decube.io/security notes: >- Compliance and security posture asserted from Decube's published security documentation. Decube is SOC 2 certified (report available on request), conducts annual third-party penetration testing, and encrypts sensitive data with dual-layer AES-256-GCM over TLS. The trust-center probe additionally surfaced ISO 27001, HIPAA, and GDPR references on the public security page. standards: - id: soc2 conforms: true evidence: "Decube is currently SOC2 certified; report available on request." - id: iso-27001 conforms: true evidence: Referenced on https://www.decube.io/security (trust-center probe). - id: hipaa conforms: true evidence: Referenced on https://www.decube.io/security (trust-center probe). - id: gdpr conforms: true evidence: GDPR/DPA handling referenced on the security page; Decube signs NDAs/DPAs where appropriate. - id: annual-pentest conforms: true evidence: Third-party penetration testing performed annually. - id: encryption-at-rest-aes-256-gcm conforms: true evidence: Dual-layer AES-256-GCM encryption for sensitive data. - id: tls-in-transit conforms: true evidence: TLS for connections; read-only credentials for source access. - id: oauth2 conforms: true evidence: MCP server authenticates via OAuth 2.0. - id: rfc9457-problem-details conforms: false evidence: No application/problem+json error contract documented.