Security
The standard we sell, applied to us first.
Anyone selling security as a service should hold themselves to the same standards they ask their customers to adopt. Here is how we do that.
Compliance
goCloudOffice holds a SOC 2 Type II attestation from an independent CPA firm: access control, change management, logging, and vendor management operate as continuously evidenced controls rather than annual paperwork. The report is available to qualified prospects through our trust center.
We support clients with HIPAA requirements. Our endpoint management platform is covered by a signed Business Associate Agreement (BAA), and we configure each client organization to meet HIPAA requirements — remote support sessions take place only with the user present, never unattended.
Trust center
Our trust center is the public home of our security posture, including our subprocessor list and our vulnerability-disclosure intake. Additional documents are published there as they are finalized; contact us for anything you need for a security review.
How we run our own IT
The same 360SmartIT Department operational stack we sell to clients is the one running our own laptops, identity, and cloud services. We run the company on the same stack we sell. Specifically:
- Identity — cloud identity with conditional access enforcing MFA and device trust on every authentication. Hardware security keys for accounts above a designated risk tier.
- Endpoints — every device enrolled in the same endpoint-management platform we run for clients, patched within 14 days of vendor release for non-critical updates, 72 hours for critical.
- Endpoint security — every goCloudOffice laptop runs the same next-generation endpoint protection we deploy for new clients: behavioral threat prevention, extended detection and response, device control, policy-based firewall management, and 24/7 threat hunting by a live team.
- Managed detection and response — elevated alerts are reviewed and acted on around the clock by a live security team with active-response playbooks — the same protection any client can layer on at their computer count.
- Secrets — credential handling follows our SOC 2 controls: least-privilege access, no plaintext storage, and rotation on defined events. We deliberately do not publish the specifics of where or how credentials are stored.
- Backups — endpoint backup through our management platform's integrated backup on every managed device, with point-in-time restore tested quarterly.
- Logging — centralized, SOC 2-compliant logging across endpoints, identity, and cloud services, with retention that meets our compliance commitments.
How our AI support desk handles your data
AISA — our AI Support Assistant — checks every drafted response against your environment before it reaches your team, grounded in a maintained environment profile (your assets, your configuration baseline, your ticket history) that is scoped to your organization by design and used to answer your organization's tickets. AISA hands off to a human engineer on defined classes — security incidents, user-lifecycle changes, billing disputes, and anything unverifiable. Every organization starts in human-released mode; direct AI posting is opt-in, and every AI-authored reply that posts directly identifies itself, signed 'Aisa — goCloudOffice AI Support Assistant.'
Vulnerability disclosure
If you find a security issue in any goCloudOffice property — this site, our customer portal, an exposed configuration, anything — we want to hear from you. Submit it through our trust portal, where our security posture and vulnerability-disclosure intake live.
- We respond within one business day.
- We commit to good-faith remediation timelines depending on severity.
- We do not pursue legal action against good-faith researchers.
- We are happy to credit researchers in our hall of fame; let us know your preference.
Data handling
Customer data is processed in the United States. The platforms that store or process customer data are enumerated in the subprocessor list in our trust center.
Material additions are notified to all customers no fewer than 30 days before they take effect.
Reporting an incident
If you are an active customer and you believe an incident affecting your data is in progress, reply to any goCloudOffice email or use the support address in your welcome packet with "INCIDENT" in the subject line, then reach our support portal. Our team monitors these continuously, and we treat confirmed incidents as our top priority. For the fastest acknowledgement, include your company name, the systems affected, and what you are observing.