Incident response process overview
Goal
Understand how BoodleBox handles security incidents, and where to report or find documentation.
How BoodleBox approaches incidents
BoodleBox maintains SOC 2 Type II certification, independently audited each year. SOC 2 Type II covers the operating effectiveness of our security controls over time — including monitoring and incident-response controls — and our data is hosted in US-based data centers.
For the authoritative description of these controls, the SOC 2 Type II report and related compliance documentation are available through the Trust Center.
Report a suspected incident or vulnerability
Email compliance@boodle.ai with what you observed, when, and any supporting detail (screenshots, error messages, the account/institution involved).
Security reports are acknowledged and reviewed by the security team. Please keep sensitive details out of public channels.
Find the documentation
Trust Center: https://trust.boodlebox.ai/ — SOC 2 Type II, HECVAT, GDPR, HIPAA, VPAT, TX-RAMP and more. Some documents are immediately viewable; others (like the full SOC 2 Type II report) are available on request through the Trust Center.
Questions?
Security and compliance: compliance@boodle.ai. General support: success@boodle.ai (typical response within 8 business hours).