Security at ContraForce

SOC 2 Type II

ContraForce is SOC 2 Type II compliant. ContraForce has successfully completed a SOC 2 Type 2 examination that verifies the legitimacy of our security controls, policies, and practices. Our SOC 2 Type II report is available to current and prospective customers upon request, subject to the appropriate non-disclosure agreements.

ISO 27001

ContraForce has completed a ISO 27001 certification. Our ISO 27001 certification demonstrates our support for protecting the confidentiality, integrity and availability of our customer data, supplier information and the internal data related to the ContraForce Security Service Delivery Platform.

Vulnerability Disclosure

ContraForce maintains a Vulnerability Disclosure Program to enable security researchers to securely report vulnerabilities they may have found.

Application Security

ContraForce uses static application security testing (SAST) to improve the security of our development process in the build pipeline. We evaluate source code to scan for vulnerabilities at every stage in development.

Security Resources

ContraForce maintains several additional online resources related to our policies, terms, and practices:
Terms of Service
Master Subscription Agreement
Privacy Policy
Vulnerability Disclosure