At VeryBusy, the security and privacy of your team's data are top priorities. Below is a comprehensive overview of the platform's infrastructure, vendor tools, and ongoing compliance measures.
🛡️ SOC 2 Compliance
VeryBusy is committed to maintaining a strong security and compliance posture aligned with industry-recognized standards.
SOC 2 Type I
VeryBusy has successfully completed a SOC 2 Type I audit, which validates that our controls were properly designed and implemented at a specific point in time in accordance with the Trust Services Criteria for Security, Availability, and Confidentiality developed and governed by the AICPA. Our SOC 2 Type I report is as of December 12, 2025, with the independent auditors' opinion issued January 7, 2026.
SOC 2 Type II (In Progress)
We are currently in an active SOC 2 Type II observation audit covering the same Trust Services Criteria, which evaluates the ongoing operating effectiveness of these controls over an extended period. The Type II report is expected in October 2026 and annually thereafter. This process demonstrates our continued commitment to consistent, real-world adherence to security best practices.
Provisioning audit trail
For Enterprise customers using SCIM provisioning, every sync event from your identity provider — user provisioned, updated, deactivated, or reactivated — is timestamped and logged, supporting our SOC 2 audit trail requirements and your own IT/compliance record-keeping.
Audit & Compliance Partners
Our SOC 2 program is managed in partnership with Drata and independently audited by Sensiba, a nationally recognized CPA firm specializing in security and compliance audits.
Assurance Documentation
An Attestation Status Confirmation from our independent auditor, summarizing the scope and status of our SOC 2 examinations, is available to any customer on request. The full SOC 2 report is available to enterprise customers, subject to standard NDA requirements.
This ongoing compliance effort supports our broader mission to provide a secure, reliable platform for managing high-value creative and production workflows.
🧱 Enterprise-Grade Account Security
We protect user access with layered authentication protocols:
All users must create a password-protected profile and verify their email before accessing any project.
Two-Factor Authentication (2FA) is available in user settings.
Single Sign-On (SSO) is supported via Google and Microsoft.
Enterprise clients can also enable enterprise SSO (OpenID Connect via Google and Microsoft Entra ID) and SCIM provisioning (Okta, Microsoft Entra ID) for centralized authentication and automated, audit-logged user management. SCIM tokens are workspace-scoped, stored only as bcrypt hashes — never in plaintext — and can be rotated or revoked instantly by the workspace owner. See how SCIM provisioning works →
☁️ Cloud Infrastructure & Data Protection
VeryBusy is hosted on Amazon Web Services (AWS), leveraging its secure and scalable cloud platform. We utilize a wide range of AWS services to ensure security and operational resilience. Additionally, we integrate third-party tools like New Relic to extend observability and application performance monitoring across our stack:
🔐 Security & Compliance
AWS WAF – Web Application Firewall
AWS Shield – DDoS protection
AWS GuardDuty – Threat detection
AWS Inspector – Automated vulnerability management
AWS Secrets Manager – Credential and token storage
AWS KMS (Key Management Service) – Key control and policy management
IAM & IAM Access Analyzer – Access control and policy validation
CloudTrail – Activity logging and auditing
📊 Monitoring & Observability
CloudWatch & CloudWatch Events – Metrics, logs, and system-level monitoring
SNS (Simple Notification Service) – Real-time alerts and notifications
New Relic – Full-stack application performance monitoring and anomaly detection
🛠️ Core Infrastructure
EC2 (Instances & Other) – Compute resources
VPC – Isolated networking and routing
Elastic Load Balancing (ELB) – High-availability traffic management
ECR & ECS – Container registry and orchestration
Lambda – Event-based serverless execution
Route 53 – Global DNS resolution
CloudFront – Content delivery and caching
CloudShell – Secure CLI management
💾 Storage & Data Management
Amazon S3 – Secure object storage
RDS – Managed relational databases
ElastiCache – Memory caching
⚙️ Automation & DevOps
CloudFormation – Infrastructure as code
Service Catalog – Pre-approved deployment configurations
Kinesis Firehose – Log streaming and delivery pipelines
🌐 Third-Party Vendors
Our current subprocessors — the third-party providers that process personal data on our behalf, what each one does, and where each is located — are listed on our Subprocessors page. We maintain that page as the single source of truth and update it whenever we add or replace a provider. Customers with a Data Processing Agreement in place receive advance notice of subprocessor changes in accordance with that agreement; anyone can request change notifications by contacting support@verybusy.io.
Transactional, account, and platform notification email is delivered through Twilio SendGrid and Amazon SES, as listed on the Subprocessors page. In addition to the subprocessors listed there, we use GitHub for source control, code review, and our CI/CD pipeline. GitHub does not process customer Workspace content.
🛡️ Network & Database Access Controls
Access to our production database is strictly limited to IPs within our VPC.
External access (including internal team members) is denied by default unless explicitly granted for maintenance or support needs.
🗂️ Content Privacy & File Management
Files are stored on Amazon S3 and served via time-limited, signed URLs.
We also use secure URLs through Imgix and other trusted infrastructure where needed.
Assets remain available until deleted by the user or workspace owner.
Deletion is user-controlled: you can delete individual assets, projects, or an entire workspace at any time, and you can request deletion of your account and content by contacting us. Content and account data may also be deleted after six (6) months of account inactivity — accounts with an active paid subscription are never considered inactive — as described in our Privacy Policy.
Application monitoring session replays are captured with all text and user input masked.
We do not access, use, or share your content except as needed to provide and maintain the Service, at your direction, or as required by law.
💳 Payment & Billing Security
All billing is handled through Stripe, a PCI DSS Level 1 certified provider.
Stripe uses secure tokenization and fraud prevention measures to protect all payment data.
📥 Security Questionnaires
If you are an enterprise customer and need to complete a security questionnaire, please contact us at enterprise@verybusy.io.

