Trust

Compliance

Last updated: July 24, 2026

This page states, honestly, where BugMojo stands on compliance — what is in place today, what is in progress, and what is on the roadmap. If you need documentation for a vendor review, everything is linked below or available on request.

SOC 2 Type I — in progress

BugMojo is pursuing a SOC 2 Type I report, working with a SOC 2 compliance-automation vendor for evidence collection and continuous control monitoring. The report is expected later this year.

To be clear about status: we are not yet SOC 2 certified. The initial scope covers the Security (Common Criteria) trust services criteria. The two controls we are furthest along on — audit-log completeness and access controls — are already implemented in the product (see the Security page). If your procurement process needs to see our kickoff plan or a bridge letter timeline, contact us and we’ll share what we can.

GDPR & CCPA

We support the core data-subject rights in the product today:

  • Data export. Users can export their personal data.
  • Erasure. Users can delete their account and associated data, and workspace admins can erase feedback submitted by a given email or device fingerprint.
  • Consent records. The extension requires explicit consent before capturing, and consent is recorded.
  • Data minimization. Network bodies are never captured and redaction runs before upload — see Security.

A Data Processing Addendum is available — see /dpa for the template and a path to request a signed copy.

Data residency

Capture artifacts are stored in US-region AWS S3 today. EU data residency is on the roadmap — it is planned, not yet available. For EU transfers, our DPA references Standard Contractual Clauses; contact us if data-residency requirements are a gating factor for your deployment.

Access control & audit logging

Role-based access control, revocable API keys, scoped MCP OAuth grants, and a company-scoped audit log (Business and Enterprise) are implemented today. These map directly to the SOC 2 access-control and audit-logging criteria. Details are on the Security page. SSO / SAML is on the roadmap for the Enterprise plan and is not yet available.

Where to get documentation

Security questionnaires

Need us to complete a vendor security questionnaire (SIG-lite or your own template)? Email security@bugmojo.com and we’ll turn it around. We maintain a set of canned answers to the most common questions so most reviews move quickly.