Trust
Compliance
Last updated: July 24, 2026
This page states, honestly, where BugMojo stands on compliance — what is in place today, what is in progress, and what is on the roadmap. If you need documentation for a vendor review, everything is linked below or available on request.
SOC 2 Type I — in progress
BugMojo is pursuing a SOC 2 Type I report, working with a SOC 2 compliance-automation vendor for evidence collection and continuous control monitoring. The report is expected later this year.
To be clear about status: we are not yet SOC 2 certified. The initial scope covers the Security (Common Criteria) trust services criteria. The two controls we are furthest along on — audit-log completeness and access controls — are already implemented in the product (see the Security page). If your procurement process needs to see our kickoff plan or a bridge letter timeline, contact us and we’ll share what we can.
GDPR & CCPA
We support the core data-subject rights in the product today:
- Data export. Users can export their personal data.
- Erasure. Users can delete their account and associated data, and workspace admins can erase feedback submitted by a given email or device fingerprint.
- Consent records. The extension requires explicit consent before capturing, and consent is recorded.
- Data minimization. Network bodies are never captured and redaction runs before upload — see Security.
A Data Processing Addendum is available — see /dpa for the template and a path to request a signed copy.
Data residency
Capture artifacts are stored in US-region AWS S3 today. EU data residency is on the roadmap — it is planned, not yet available. For EU transfers, our DPA references Standard Contractual Clauses; contact us if data-residency requirements are a gating factor for your deployment.
Access control & audit logging
Role-based access control, revocable API keys, scoped MCP OAuth grants, and a company-scoped audit log (Business and Enterprise) are implemented today. These map directly to the SOC 2 access-control and audit-logging criteria. Details are on the Security page. SSO / SAML is on the roadmap for the Enterprise plan and is not yet available.
Where to get documentation
- Security overview — data handling, redaction, encryption, access control.
- SDK performance & overhead — bundle sizes and runtime behavior.
- Data Processing Addendum — template and signed-copy request.
- Subprocessors — the third parties we use to run the service.
- Vulnerability Disclosure Policy — safe harbor, scope, response times.
- Privacy Policy
Security questionnaires
Need us to complete a vendor security questionnaire (SIG-lite or your own template)? Email security@bugmojo.com and we’ll turn it around. We maintain a set of canned answers to the most common questions so most reviews move quickly.

