Software Secured Company Logo.
Services
Services
WEB, API & MOBILE SECURITY

Manual reviews expose logic flaws, chained exploits, and hidden vulnerabilities

Web Application Pentesting
Mobile Application Pentesting
Secure Code Review
Infrastructure & Cloud Security

Uncovers insecure networks, lateral movement, and segmentation gaps

External Network Pentesting
Internal Network Pentesting
Secure Cloud Review
AI, IoT & HARDWARE SECURITY

Specialized testing validates AI, IoT, and hardware security posture

AI Pentesting
IoT Pentesting
Hardware Pentesting
ADVANCED ADVERSARY SIMULATIONS

We simulate attackers, exposing systemic risks executives must address

Red Teaming
Social Engineering
Threat Modelling
PENETRATION TESTING AS A SERVICE

PTaaS provides continuous manual pentests, aligned with release cycles

Penetration Testing as a Service
OWASP TOP 10 TRAINING

Practical security training strengthens teams, shifting security left effectively

Secure Code Training

Ethical Hacking

Services Overview

Black arrow icon

Enterprise Deal Support

Services Overview

Black arrow icon
Ready to get started?
Identify real vulnerabilities confidently with zero-false-positive penetration testing
Learn More
Industries
Industries
INDUSTRIES
Data and AI

AI pentesting uncovers adversarial threats, ensuring compliance and investor trust

Healthcare

Penetration testing protects PHI, strengthens compliance, and prevents healthcare breaches

Finance

Manual pentests expose FinTech risks, securing APIs, cloud, and compliance

Security

Penetration testing validates SecurTech resilience, compliance, and customer trust

SaaS

Pentesting secures SaaS platforms, proving compliance and accelerating enterprise sales

CASE STUDY

“As custodians of digital assets, you should actually custodize assets, not outsource. Software Secured helped us prove that our custody technology truly delivers on that promise for our clients in both the cryptocurrency and traditional finance”

Nicolas Stalder,
CEO & Co-Founder, Cordial Systems
Black arrow icon
Ready to get started?
Our comprehensive penetration testing and actionable reports have 0 false positives so you can identify
Learn More
Compliance
Compliance
COMPLIANCE
SOC 2 Penetration Testing

Pentesting validates SOC 2 controls, proving real security to auditors and customers

HIPAA Penetration Testing

Manual pentesting proves HIPAA controls protect PHI beyond documentation

ISO 27001 Penetration Testing

Pentests uncover risks audits miss, securing certification and enterprise trust

PCI DSS Penetration Testing

Pentesting validates PCI DSS controls, protecting sensitive cardholder data

GDPR Penetration Testing

GDPR-focused pentests reduce breach risk, regulatory fines, and reputational loss

CASE STUDY

“Software Secured’s comprehensive approach to penetration testing and mobile expertise led to finding more vulnerabilities than our previous vendors.”

Kevin Scully,
VP of Engineering, CompanyCam
Black arrow icon
Ready to get started?
Our comprehensive penetration testing and actionable reports have 0 false positives so you can identify
Learn More
PricingPortal
Resources
Resources
resources
Blogs
Case Studies
Events & Webinars
Partners
Customer Testimonials
News & Press
Guides and Checklists
About Us
cybersecurity and secure authentication methods.
Black arrow icon
API & Web Application Security Testing

Attack Chains: The Hidden Weakness in Modern API & Web Application Security

Alexis Savard
November 21, 2025
Ready to get started?
Our comprehensive penetration testing and actionable reports have 0 false positives so you can identify
Learn More
Login
Book a Consultation
Deal Blocked?
Legal

Security & Compliance

Learn about our security program, SOC 2 compliance, secure development practices, vulnerability management, AI governance, and the documentation available to support vendor security reviews.

Table of contents
Text Link
Text Link

SOC 2 Status

Completed an independent SOC 2 Type 1 audit evaluating the design of our security controls.

Currently in the observation period for our SOC 2 Type 2 audit and expect our Type 2 report to be available in Q3 of this calendar year (target: October 2026).

SOC 2 reports are available to customers and qualified prospects upon request, subject to a non-disclosure agreement (NDA).

People Security

Software Secured maintains administrative, operational, and personnel security controls to protect customer information throughout every engagement.

Our People Security program includes:

  • Mandatory security awareness training for all employees
  • Background checks conducted before employment
  • Documented information security policies 
  • Least-privilege access to customer data

For more information about how personal information is collected, used, and protected, please review our Privacy Policy.

Physical Security

Software Secured maintains physical safeguards to protect employees, systems, and customer information.

Our Physical Security program includes:

  • Secure office access with controlled entry
  • Visitor management procedures and escorted access where appropriate
  • Clean desk and clean screen requirements for sensitive information
  • Secure storage of confidential documents and portable media
  • Screen locking requirements for unattended workstations
  • Secure disposal and destruction of storage media and retired equipment
  • Physical asset management and device protection

Identity & Access Management

Access to customer systems and data is governed by the principle of least privilege and supported through layered identity and access controls.

Our Identity & Access Management program includes:

  • Role-Based Access Control (RBAC)
  • Least-privilege access to customer systems and data
  • Strong password requirements and unique credentials for business systems
  • Company-approved password manager for credential storage
  • Multi-factor authentication (MFA) is supported, with additional protection for privileged accounts
  • Annual access reviews
  • Access is removed or modified following employee departures or role changes.
  • Secure remote access using encrypted VPN connections where required

Secure Development Lifecycle

Security is integrated throughout the design, development, testing, and deployment of our platform through documented secure engineering practices.

Our Secure Development Lifecycle includes:

  • Threat modeling for new products, services, and significant features
  • Manual secure code reviews and peer review of production code
  • Continuous Static Application Security Testing (SAST)
  • Software Composition Analysis (SCA) to identify vulnerable dependencies
  • Dynamic Application Security Testing (DAST)
  • Segregated production, staging, and development environments
  • Developers do not have direct access to production environments
  • Secure remote administrative access where required
  • Logical customer data isolation to support logical data isolation
  • Automatic session timeouts after 30 minutes of inactivity

Vulnerability Management

As a penetration testing company, we apply the same vulnerability management practices internally that we recommend to our customers.

Our vulnerability management program includes:

  • Quarterly manual penetration testing of production environments
  • Regular secure code reviews
  • Centralized tracking of confirmed vulnerabilities
  • Risk-based vulnerability prioritization
  • Validation and retesting of remediated vulnerabilities

Confirmed vulnerabilities are remediated in accordance with documented service-level objectives.

SeverityTarget Remediation
CriticalBefore release or within 5 business days
HighBefore release or within 30 business days
MediumWithin 90 business days
LowWithin 180 business days

Infrastructure & Monitoring

Software Secured protects its production environment through layered infrastructure security, system hardening, and security monitoring.

Our infrastructure and monitoring program includes:

  • Segregated production, staging, and development environments
  • Web Application Firewall (WAF) to help protect internet-facing applications
  • Intrusion Detection and Prevention Systems (IDS/IPS)
  • Centralized logging and security event monitoring
  • Administrative activity logging for privileged actions
  • Secure server configuration baselines and periodic server audits
  • Regular operating system and security patch management
  • Endpoint protection and anti-malware software on business systems
  • Full disk encryption for company-managed laptops and mobile devices

Risk Management & Business Continuity

Software Secured maintains a documented risk management and business continuity program to support the resilience of our services and protect customer information.

Our Risk Management & Business Continuity program includes:

  • Formal risk assessments and ongoing risk management activities
  • Vendor security reviews before onboarding third-party service providers
  • Periodic reviews of third-party vendors and subprocessors
  • Documented Incident Response Plan with defined escalation procedures
  • Annual incident response exercises to validate response readiness
  • Business Continuity Plan (BCP)
  • Disaster Recovery Plan (DRP)
  • Encrypted backups and documented recovery procedures
  • Security incident notification processes where contractually required
  • Responsible Vulnerability Disclosure Program

Insurance Coverage 

Software Secured maintains insurance, including: 

  • Commercial General Liability
  • Technology Errors & Omissions (Professional Liability) 
  • Network Security and Privacy Liability (Cyber Liability) 

AI Governance

Software Secured maintains a documented AI Usage Policy that enables responsible AI use while protecting customer information.

Our AI governance program includes:

  • Customer data may be processed only with approved private AI services, hosted locally eg. Private Bedrock Instance.
  • Approved AI tools may be used for internal productivity, research, documentation, and other business purposes only when customer data is not involved.
  • Employees receive guidance on the appropriate use of AI tools and are required to report any suspected unauthorized disclosure of customer information.

Security Documentation

Software Secured provides security documentation to support customer security reviews and vendor risk assessments.

Publicly Available
  • Privacy Policy
  • Responsible Disclosure Process
  • Terms and Conditions
  • Subprocessor List
Available Upon Request (NDA may be required)
  • Secure Engineering Policy
  • SOC 2 Report
  • Security Questionnaire
  • Data Processing Agreement (DPA)
  • Business Continuity Summary
  • Incident Response Summary

To request security documentation, please contact our team at info@softwaresecured.com.

Responsible Disclosure

Software Secured welcomes responsible disclosure of security vulnerabilities that may affect our systems, applications, or services.

If you believe you have identified a security vulnerability affecting our systems or services, please report it with sufficient detail to reproduce the issue. If you believe you have identified a security vulnerability affecting our systems or services, please report it with sufficient detail to reproduce the issue.

Upon receiving a report, we will:

  • Acknowledge receipt promptly
  • Investigate and validate the reported issue
  • Prioritize remediation based on severity and potential impact
  • Work to resolve verified vulnerabilities in accordance with our Vulnerability Management Program
  • Maintain communication with the reporter throughout the investigation, where appropriate

Please submit vulnerability reports to info@softwaresecured.com.

Last Updated: July 2026

Helping companies identify, understand, and solve their security gaps so their teams can sleep better at night

Book a Consultation
Centralize pentest progress in one place
Canadian based, trusted globally
Actionable remediation support, not just vulnerabilities
Clutch logo
Web, API, Mobile Security
Web App PentestingMobile App PentestingSecure Code Review
Infrastructure & Cloud Security
External Network PentestingInternal Network PentestingSecure Cloud Review
AI, IoT & Hardware Security
AI PentestingIoT PentestingHardware Pentesting
More
PricingPortalPartnersContact UsAbout UsOur TeamCareers
More Services
Pentesting as a ServiceSecure Code Training
Industries
Data and AIFinanceHealthcareSecuritySaaS
Compliance
GDPR PentestingHIPAA PentestingISO 27001 PentestingPCI DSS PentestingSOC 2 Pentesting
Resources
BlogsCase StudiesEvents & WebinarsCustomer TestimonialsNews & PressWhitepapers
More
PricingPortalPartnersContact UsAbout UsOur TeamCareers
Resources
BlogsCase StudiesEvents & WebinarsCustomer TestimonialsNews & PressWhitepapers
Comparisons
Software Secured vs Cobalt
Security & ComplianceSubprocessorsPrivacy PolicyTerms & Conditions
2026 ©SoftwareSecured