SOC2 compliant with bubble hosted websites

Does anyone have experience becoming SOC2 compliant and including bubble hosted websites within the scope?

I know that bubble has become SOC2 compliant recently and that’s great! However, if a software development company is becoming SOC2 compliant, it may need to include the bubble apps it makes within it’s scope.

I have done a little research and see a possible challenge for reporting within the bubble ecosystem. In particular reporting when pushing a new change from the main branch to the live environment.

If anyone has ideas or experience I would appreciate it. Thanks!

3 Likes

We are currently in the process of getting soc 2 certified with a Bubble app. It’s challenging, right now I’m trying to figure out how to manage Log Management Configurations and Alerts given we are currently on the Growth plan and this type of configuration is available on the enterprise plan only it seems