# SOC 2 Type 2 Certified

## Your secrets stay secrets.

Code, credentials, and test data. All encrypted in transit, isolated in execution, and destroyed on completion. SOC 2 Type 2 certified. GDPR compliant.

## Security baked in. Not bolted on.

Data isolation, encryption, and AI privacy from day one.

### The old way

- ✗ Upload your app to an unknown cloud
- ✗ Hope your data stays private
- ✗ Wonder if your test data trains their AI
- ✗ Wait 6+ weeks to pass security review

### The Pie way

- ✓ SOC 2 Type 2 certified infrastructure
- ✓ GDPR compliant data handling
- ✓ Your data never trains any AI model
- ✓ Pass security reviews in days, not months

## Independently audited. Continuously.

SOC 2 Type 2 means ongoing verification that our controls work. Automated through Sprinto across 41 continuous controls.

### Security

Systems protected against unauthorized access. RBAC, encryption, isolated environments.

### Availability

Enterprise-grade cloud infrastructure with 99.9%+ uptime commitment.

### Confidentiality

Application data, test credentials, and results are encrypted and access-controlled.

## Your data never trains our AI.

Your data is never sent upstream to train models. Not ours. Not anyone else's.

### No upstream training

Your test data is never sent to train external AI models.

### Isolated optimization

We tune Pie for your app, but that stays with you.

### No data leakage

Your information never benefits other customers.

## Created. Executed. Destroyed.

Actual isolation. Not virtual separation on shared infrastructure.

### 1. Created

Fresh sandboxed environment spins up.

### 2. Executed

Test runs in complete isolation.

### 3. Destroyed

Environment wiped immediately.

- ✓ No cross-contamination
- ✓ No persistent data
- ✓ No data bleeding
- ✓ Clean every time

## Encrypted everywhere. No exceptions.

Every piece of data that touches Pie is encrypted. From the moment it enters until the moment it leaves.

### In Transit

- ✓ TLS 1.2+ for all data transmission
- ✓ No unencrypted connections accepted
- ✓ Certificate pinning for mobile builds

### At Rest

- ✓ AES-256 encryption (same standard banks use)
- ✓ Encrypted application builds
- ✓ Encrypted test results and logs

### Test Credentials

- ✓ Stored in secure, encrypted vault
- ✓ Accessed only during test execution
- ✓ Wiped with ephemeral environment

## GDPR compliant.

For teams with EU users.

### Data minimization

We collect only what's needed for testing.

### Purpose limitation

Your data used for your tests only.

### Storage limitation

Ephemeral environments destroyed after runs.

### Right to erasure

Request deletion anytime.

## Frequently Asked Questions

### Is Pie SOC 2 Type 2 certified?

Yes. We hold SOC 2 Type 2 certification across security, availability, and confidentiality trust principles. Sprinto handles our continuous compliance monitoring, tracking 41 control points in real time so our certification stays current—not something we dust off once a year.

### Is Pie GDPR compliant?

Yes. Full GDPR compliance for EU data handling. We practice data minimization (collecting only what's needed for testing), purpose limitation (your data used only for your tests), and support right to erasure on request. Test environments are ephemeral: created for each run and destroyed immediately after.

### Does my data train your AI models?

No. Your data is never sent upstream to train models. This is a contractual guarantee. Your test data, application behavior, and results stay in your isolated environment. Any app-specific optimizations stay with you.

### What encryption standards do you use?

AES-256 encryption for all data at rest, including application builds, test results, and logs. TLS 1.2+ for all data in transit. We don't accept unencrypted connections. Test credentials are stored in a separate encrypted vault, accessed only during active test execution.

### Are test environments shared between customers?

No. Every test runs in a completely isolated, sandboxed environment that's created on-demand for your test and destroyed immediately after execution. No data persists. No cross-contamination between customers. Actual isolation, not virtual separation on shared infrastructure.

### How do you handle test credentials?

Test credentials are stored in an encrypted vault, not in config files or plain text. They're accessed only by AI agents during active test execution within your isolated environment. When the test completes, credential access is wiped. You can add, update, or revoke credentials anytime through the platform.

### What access controls do you have?

Role-based access control (RBAC) across the platform. Assign users as Admins (full access), Test Engineers (create and run tests), Viewers (read-only results), or create custom roles. Every action is logged with timestamps and user attribution. Audit trails are available when you need them.
