Security · SOC 2
SOC 2: in progress.
That is the honest status, and it is the same status the front page has carried since launch. Below is what that means, and what is in place while the audit runs.
Bursar does not hold a completed SOC 2 report today. Nothing on this site should be read as claiming one. If your review requires an attestation before you can proceed, tell us now rather than after a pilot - we would rather lose the deal than be the reason your diligence file is wrong.
What is in place today.
Independent of the audit, and true now rather than on completion.
Encryption
AES-256 at rest and in transit, on every store and every hop.
Access control
Default-deny on every route, tenancy resolved from a verified identity, and a separate credential gate on the act of signing off a close.
Audit logging
An immutable record of every action taken on a close, retained with the close.
Data lifecycle
Export on request; deletion within 30 days of offboarding.
Consent gating
Where the law requires a signed client consent before disclosure, the close cannot be opened without it.
Questions this page gets asked.
Can we run a vendor security review before SOC 2 completes?
Yes, and most firms do. Email hello@trybursar.com with your questionnaire and you will get it answered directly rather than pointed at a badge.
Will you sign our client’s security addendum?
That is a contract question rather than a status question, so it is answered case by case - send it over.
What happens to the answer if the status changes?
This page is the status. When the report exists it will say so here, with the period it covers and the auditor, and not before.
Security review
Run your review now, not after.
If an attestation is a hard requirement for you today, better to know before a pilot than after one.