← All Documents
Legal · Document 09
Revision 2026.08 · Confidential
Trust · Security · SOC 2
Security
& Compliance.
How SlabOS protects your shop's quotes, your customers' personal information, and your pricing — the data you'd never hand to a competitor. Our controls are designed and operated against the five SOC 2 Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Framework
SOC 2 (AICPA TSC 2017)
Data Residency
Encrypted at rest & in transit
Tenant Model
Row-level isolation per shop
Uptime Target
99.9% / month (see SLA)

This document describes SlabOS LLC's security program and is provided for informational and due-diligence purposes. It is not a substitute for an executed SOC 2 report, which is available under NDA to qualified prospects and customers on request.

SLBOS-LEGAL-09
Contents

1.Overview & Attestation Status

SlabOS is a multi-tenant SaaS platform for countertop fabricators. Every shop ("Tenant") stores its accounts, quotes, jobs, crew schedules, slab inventory, and — most sensitively — its pricing on the SlabOS platform. We treat that data as if our business depended on protecting it, because it does.

Our security program is built and operated against the AICPA SOC 2 Trust Services Criteria (2017). The criteria break into five categories; Sections 2–6 of this document map our controls to each.

Attestation status — complete before distributing. Replace this box with your current, accurate status. A SOC 2 claim in a customer-facing document carries legal and contractual weight, so the wording must match reality exactly:
  • If a report is complete: “SlabOS completed its SOC 2 Type I / II examination on date, covering the period period, audited by firm. The full report is available under NDA.”
  • If an audit is in progress: “SlabOS is undergoing its SOC 2 Type examination, expected date. Controls described below are in operation today.”
  • If controls are mapped but no auditor engaged: “SlabOS operates a SOC 2–aligned control set (described below) and is preparing for formal examination.”

Regardless of report timing, the controls in this document are in operation today. Sections 2–10 describe what we actually do, not aspirations.

2.Security (Common Criteria)

The Common Criteria (CC-series) are the backbone of every SOC 2 engagement — the controls that protect the system against unauthorized access, whether logical or physical.

Authentication & Credentials

Authorization

Application-Layer Hardening

Change Management & Code

3.Availability

SlabOS targets 99.9% monthly uptime, formalized in the Service Level Agreement (Document 07) with automatic service credits when we miss.

4.Confidentiality & Pricing Secrecy

A fabricator's price list is its most competitively sensitive asset. SlabOS treats pricing confidentiality as a first-class control, reinforced contractually in the Data Processing Agreement (Document 04).

5.Processing Integrity

Quotes and invoices are only useful if the math is right and the data is complete and timely.

6.Privacy

SlabOS processes the personal information of our customers' staff and their end customers (names, addresses, phone numbers, email). Our handling is described in the Privacy Policy (Document 03) and is PIPEDA-, CCPA-, and US state-privacy-law-aware.

7.Tenant Isolation Architecture

SlabOS is multi-tenant by design. Isolation is enforced in the data model, not bolted on:

Why not a database per customer? Logical isolation with a tenantId on every row gives equivalent confidentiality with far better reliability and recoverability than dozens of separate databases. The control that matters — “Tenant A can never read Tenant B’s data” — is enforced and testable either way.

8.Subprocessors

SlabOS relies on a small set of vetted infrastructure providers. Each is bound by its own security commitments; the current list is maintained in the DPA and reproduced here for transparency.

Material changes to this list are communicated to customers per the DPA's subprocessor-notification clause. Replace provider names with your contracted entities before publishing if you prefer to name them explicitly.

9.Incident Response & Business Continuity

10.Reporting a Vulnerability

We welcome good-faith security research. If you believe you've found a vulnerability, email security@slabos.org with details and reproduction steps. We commit to acknowledge within two business days, keep you updated through remediation, and not pursue action against researchers acting in good faith under a standard safe-harbor.

Due Diligence
Need the full
report?
Security questionnaires, the executed SOC 2 report, our penetration-test summary, and subprocessor agreements are available to qualified prospects and customers under NDA. We answer security review fast — it's usually the shortest part of the sales cycle, because the work is already done.
Trust / Legal legal@slabos.org
Status status.slabos.org
Companion Docs DPA (04) · SLA (07) · Privacy (03)
SlabOS LLC · An Illinois limited liability company · Revision 2026.08 All legal documents →