CERTIFICATIONS, COMPLIANCE, & SECURITY

Your data is safe with Campfire.

We hold ourselves to the highest independent security standards. Not as a checkbox, but as a commitment to every customer who trusts us with their data.

  • Audit Type: Continuous, not point-in-time

  • Verification: Independent third-party auditors

  • Reports Available: Upon request under NDA

Certified & Current

SOC 1 Type II
Controls relevant to financial reporting. Type II means our controls were tested continuously over a full audit period, not just at a single point in time.

SOC 2 Type II
Covers all five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Independently audited over time, not just a snapshot. Continuously verified.

Audit Year 1 Underway

ISO 27001
The international standard for Information Security Management Systems. We have entered our first formal audit year and are on track for full certification by end of 2026.

Framework Aligned

GDPR, CIS Controls & NIST CSF — Framework Aligned
Our security program is built in alignment with globally recognized frameworks — GDPR for data privacy, CIS Controls for prioritized security best practices, and NIST CSF for risk-based cybersecurity governance.

Security Practices

  • Multi-Factor Authentication: Enforced across all systems and privileged access points

  • Least-Privilege Access: With quarterly reviews and prompt deprovisioning on departure

  • Encryption at Rest & in Transit: AES-256 and TLS 1.2+ for all sensitive data

  • Formal Risk Assessment: Program with a maintained risk register and documented treatment plans

  • Vendor & Third-Party Risk Management: With due diligence for all critical suppliers

  • Documented Incident Response Plan: With tested procedures and defined escalation paths

  • Business Continuity & Disaster Recovery Plans: Tested at least annually

  • Continuous Monitoring & Logging: Of systems, user activity, and security events

  • Annual Security Awareness Training: For all staff, with phishing simulations

  • Formal Change Management: With peer review and documented approval workflows

  • Vulnerability Management & Patching: With SLAs defined by severity classification

  • Data Classification & Retention Policies: Governing handling of all customer data

  • Endpoint Protection & MDM: Deployed across all corporate devices

icon_shield_campfire_interactive_1x

Download the full Security & Compliance document

Review our complete certifications and security practices or share with your team.

Frequently asked questions

Is Campfire SOC 2 certified?

Yes. Campfire holds both SOC 1 Type II and SOC 2 Type II certifications. Both are continuously audited by independent third-party auditors — not just verified at a single point in time. Reports are available upon request under NDA.

What is SOC 2 Type II and why does it matter?

SOC 2 Type II covers all five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Type II means our controls are tested continuously over a full audit period, giving you confidence that our security posture is consistent — not just compliant on paper.

What compliance frameworks does Campfire align to?

Our security program is built in alignment with GDPR for data privacy, CIS Controls for prioritized security best practices, and NIST CSF for risk-based cybersecurity governance.