---
title: "Cloud Marketplace Security & Compliance: SOC 2, GDPR"
url: https://www.suger.io/resources/security/
canonical: https://www.suger.io/resources/security/
type: Resource
description: "Cloud marketplace security and compliance built in: SOC 2 Type II certified, GDPR-compliant, with TLS 1.3 and AES-256 encryption on every request."
---

# Cloud Marketplace Security & Compliance: SOC 2, GDPR

> Canonical HTML version: https://www.suger.io/resources/security/

1.  [Home](/)
2.  /
3.  [Resources](/resources/)
4.  /
5.  Security

Security & Privacy

# Enterprise-grade security for your marketplace data.

SOC 2 Type II certified, ISO/IEC 27001 certified, and GDPR-compliant, with TLS 1.3 and AES-256 encryption everywhere. The same security posture trusted by Intel, Snowflake, and Fireblocks.

Compliance & certifications

![SOC 2 Type II](/logos/soc2-badge.svg)

### SOC 2 Type II

Annual security audit certification

![ISO/IEC 27001](/logos/iso27001-badge.webp)

### ISO/IEC 27001

Information security management certified

![GDPR](/logos/gdpr-badge.svg)

### GDPR

EU data protection compliance

How we protect your data

## Our security principles

### Encryption everywhere

All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Your sensitive information is always protected.

### Zero-trust architecture

Every request is authenticated and authorized. We follow the principle of least privilege across our entire infrastructure.

### Secure infrastructure

Hosted on AWS in the United States across multiple availability zones, with automated backups.

### Regular audits

We undergo regular third-party security audits, penetration testing, and vulnerability assessments.

Enterprise controls

## Built for enterprise security teams

Suger provides the controls enterprise security reviews ask for — OIDC SSO, SCIM provisioning, role-based access, and a queryable audit trail.

[View Privacy Policy](/privacy/)

OIDC single sign-on

SCIM user provisioning

Multi-factor authentication (MFA)

Role-based access control (ADMIN / EDITOR / VIEWER)

Audit log, queryable over the API

Per-organization rate limiting

API key and OAuth client credentials

HMAC-signed webhooks

Control matrix

## Controls, and which plans have them

Every control below is in effect today. Where a control is limited to a plan, the scope column says so.

Area

Control

Scope

Data location

Customer data is stored and processed in the United States, on AWS.

All plans

Tenant isolation

Every record belongs to one organization. All API paths are org-scoped, and each request must prove membership of the organization it targets before any data is read.

All plans

Authentication

Two credentials: an organization API key, or an OIDC bearer token verified against the issuer's published keys. Identity is never taken from a request header.

All plans

Single sign-on

OIDC SSO with SCIM user provisioning, configured self-service in the console.

Growth and Enterprise

Multi-factor auth

MFA on user accounts, including administrative reset.

All plans

Authorization

Role-based access control with ADMIN, EDITOR and VIEWER roles. No identity is granted editor access across all organizations.

All plans

Audit trail

Auditing events are a first-class resource you can query over the API, not just a console view.

All plans

Secrets

Credentials are held in a managed secrets service and referenced indirectly. They are not stored in configuration.

All plans

Abuse protection

Rate limiting is applied per organization and fails closed — if the limiter cannot be consulted, the request is rejected rather than allowed.

All plans

Webhook integrity

Outbound webhooks are HMAC-signed and carry an X-Suger-Signature-256 header you verify before trusting the payload.

All plans

Encryption

TLS 1.3 in transit and AES-256 at rest, with keys managed by the cloud provider's KMS.

All plans

Custom security policies

Bespoke controls negotiated as part of an enterprise agreement.

Enterprise only

Shared responsibility

## Who is responsible for what

Suger is a processor sitting between your systems and the cloud marketplaces. This is where the line falls.

Area

Suger

You

Platform, infrastructure and encryption

Runs, patches and monitors the service; manages encryption and key rotation.

None.

Who can access your Suger organization

Enforces roles and org boundaries on every request; provides SSO and SCIM.

Decides who is invited, assigns roles, and deprovisions leavers.

Marketplace and CRM credentials you connect

Stores them in a managed secrets service and uses them only for your organization's operations.

Grants the narrowest scope that works, and rotates on your own schedule.

API keys and OAuth clients

Issues, scopes and validates them.

Keeps them secret, rotates them, and revokes on compromise.

What data you send to Suger

Processes it under the DPA and the terms.

Decides what to send; Suger does not require personal data beyond user accounts.

Reviewing the audit trail

Records events and exposes them over the API.

Reviews them, and exports to your SIEM if you keep one.

### How your data flows

Suger sits between three parties and holds no data that does not belong to one of those relationships:

1.  **Your systems → Suger.** Your CRM, billing and metering systems connect with credentials you authorize per organization. You choose the scope.
2.  **Suger → the marketplaces.** Suger calls AWS, Microsoft, Google Cloud, Snowflake, Alibaba Cloud and Oracle on your behalf using the marketplace credentials you connect.
3.  **The marketplaces → Suger → you.** Entitlements, usage and disbursement flow back, are reconciled, and are pushed to your finance systems or read over the API.

Every hop is authenticated, scoped to one organization, and recorded in the audit trail. Suger does not require end-customer personal data beyond the user accounts you create.

### Requesting evidence

Enterprise customers and prospects under NDA can request the SOC 2 Type II report, the ISO/IEC 27001 certificate, penetration test summaries, and completed security questionnaires. Email [security@suger.io](mailto:security@suger.io) and state which documents you need and the review deadline.

A Data Processing Agreement is available to all customers — see the [privacy policy](/privacy/) and [GDPR commitment](/gdpr/).

Published May 29, 2026 · Last reviewed August 2, 2026

Written and maintained by the Suger team.

Spotted something out of date? Email [security@suger.io](mailto:security@suger.io) and we will correct it.

Responsible disclosure

## Report a security vulnerability

We value the security community's help in keeping Suger and our customers safe. If you discover a vulnerability, please report it responsibly.

### Our commitments

Acknowledge all reports within 48 hours

Keep reporters informed of remediation progress

No legal action against good-faith researchers

Coordinate on disclosure timelines

### What we ask

Provide sufficient detail to reproduce the issue

Allow reasonable time before public disclosure

Avoid disrupting services or accessing others' data

FAQ

## Security questions, answered

Is Suger SOC 2 compliant? +

Yes. Suger is SOC 2 Type II certified, with annual third-party audits covering security, availability, and confidentiality. The report states the audited scope; it is available to enterprise customers and prospects under NDA from security@suger.io.

Is Suger ISO/IEC 27001 certified? +

Yes. Suger is certified against ISO/IEC 27001, the international standard for information security management systems (ISMS), covering risk management, access control, and continuous security improvement. The certificate is available to enterprise customers on request.

Is Suger GDPR compliant? +

Yes. Suger complies with GDPR requirements for EU data protection, including lawful processing, data subject rights, and cross-border transfer safeguards. A Data Processing Agreement (DPA) is available for all customers.

How does Suger encrypt customer data? +

All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Encryption keys are managed through cloud provider KMS services with automatic rotation.

Where is Suger data hosted? +

Suger runs on AWS in the United States, across multiple availability zones, with automated backups. All customer data is stored and processed in the US today. If your procurement requires data residency in another region, raise it with security@suger.io before contracting.

Does Suger support SSO and MFA? +

Yes. Suger supports OIDC single sign-on and SCIM user provisioning, set up self-service in the console, on Growth and Enterprise plans. Multi-factor authentication is available to all users on every plan. If your identity provider requires SAML rather than OIDC, contact security@suger.io.

Is my data isolated from other Suger customers? +

Yes. Every record belongs to exactly one organization, every API path is scoped to an organization, and each request must prove membership of the organization it targets before any data is read. Identity is never taken from a request header.

Can I see who did what in my Suger account? +

Yes. Auditing events are a first-class resource you can query over the API, not just a console view, so you can export them into your own SIEM or review tooling.

How do I report a security vulnerability? +

Email security@suger.io with details of the vulnerability. We acknowledge all reports within 48 hours and coordinate on remediation and disclosure timelines. See our responsible disclosure policy below.

Can I get Suger's security documentation? +

Enterprise customers can request our SOC 2 Type II report, penetration test summary, and security questionnaire responses. Contact security@suger.io or schedule a call with your sales rep.

## Have security questions?

Our security team is here to help. Request our SOC 2 report, DPA, or schedule a security review.

[Contact Security Team](/contact-us/) [Privacy Policy](/privacy/)
