Enterprise technology

Security and trust

Work confidently using reliable and secure enterprise technology.

Access Security Docs

Information security controls

The Checkbox platform is highly secure with layers of technical and operational controls in place to protect information. Checkbox maintains an Information Security Management System as part of its governance framework which includes policies and procedures around network security, information handling and data security, access control, incident response, backups, change management, risk management, vulnerability/patch management, & vendor risk management.

Encryption of Data at Rest and In Transit

Automated Security Patching

Antivirus Scanning

Network-based Intrusion Detection Systems (NIDS)

Regular Web Application Penetration Testing

Regular Automated Vulnerability Scanning

Hardened Standard Operating Environment Images

Firewall Policies at the Host and Service Level (Micro Network Segmentation)

Monitoring and Logging of All Administrative Access & Network Traffic Flows

GCC SOC 2 verified badge

Checkbox is SOC 2 Type II Attested

Checkbox has been externally audited against the security requirements of the SOC 2 framework, and has successfully completed a SOC 2 Type II examination.

GCC ISO/IEC 27001 certified badge

Checkbox is ISO 27001 Certified

Checkbox has been externally audited against the security requirements of the ISO/IEC 27001:2022 framework, and has achieved ISO 27001 certification.

GCC ISO/IEC 27017 certified badge

Checkbox is ISO 27017 Compliant

Checkbox has been externally audited against the security requirements of the ISO/IEC 27017:2015 framework, and is ISO 27017 compliant.

GCC ISO/IEC 27018 certified badge

Checkbox is ISO 27018 Compliant

Checkbox has been externally audited against the security requirements of the ISO/IEC 27018:2019 framework, and is ISO 27018 compliant.

Trusted by leading legal teams, globally

Access our security documents

Get in touch to request Checkbox's security documents including policies, penetration tests and SOC2 audit reports.