SOC 2
Operational security controls — security, availability, confidentiality, and processing integrity of customer data across the platform.
ALIGNED · TYPE II IN ROADMAP| File ref | GFP-SEC-26.10 |
| Revision | 26.10 |
| Claims reviewed | 2 October 2026 |
| Next review due | 2 January 2027 |
| Live page | gofindpart.com/security/ |
Industrial supply is where a wrong part can idle a production line for a shift. The platform routing those orders needs to not flinch.
This page is the whole security posture — every control we run, the standards we're aligned to, and the gaps we're honest about. No certification-mongering. No theatre. A single page you can print. How those controls protect an order is on the trust page.
Where the industry converges, so do we. These aren't certifications yet — they're the control frameworks our engineering & ops decisions are measured against internally, with an active roadmap to formal audit.
Operational security controls — security, availability, confidentiality, and processing integrity of customer data across the platform.
ALIGNED · TYPE II IN ROADMAPInternational standard for information security management systems — policy, risk assessment, and continuous improvement of controls.
ALIGNED · CERT. IN ROADMAPEU & UK GDPR compliance — lawful basis, data minimisation, subject-access, retention & deletion. Enforced at the platform level, not bolted on.
COMPLIANT · ONGOINGGoFindPart is not currently certified for SOC 2 or ISO 27001. These represent standards we design against and are actively working towards. We would rather tell you the true state of our security posture — and what we're doing to improve it — than sticker-badge a page and hope you don't look closely. Our roadmap to formal audit is below. Where this page says PCI-DSS Level 1, it describes our payment processor, Stripe; our own PCI self-assessment is on that roadmap too.
We use Aikido Security to scan our source code, our cloud accounts (AWS, Google Cloud and Azure) and our public web addresses for known weaknesses. You can ask for the security report Aikido produces from those scans — the badge opens Aikido's request form.
The report comes from an automated tool, so it is not an independent audit and not a certification.
Aikido's form asks for your name, your company and your email address, which reach Aikido and us so that we can answer your request — see section 2.7 of our Privacy Policy.
Nine control groups. The technical measures that run on the platform, grouped by what they protect. No marketing categories, no fluff — these are the controls shipped in the codebase and infrastructure, checked against the repositories on the review date above.
Security is a schedule, not a sticker. This is what's shipped today versus what we're executing against for the remainder of 2026.
If you've discovered a security vulnerability in GoFindPart — or even just something that looks off — we'd rather hear about it directly than read about it. Good-faith disclosure is protected, encouraged, and credited.
Procurement, infosec review, vendor questionnaire, security-documentation request — we respond to all of it. No sales filter, no "schedule a call" wall.
This document is the security page at gofindpart.com/security/ as published on the review date above. Every claim in it has a row in GoFindPart's claims register naming its evidence, and the site's build fails when a claim and its row disagree.
Questions, vendor questionnaires and security-documentation requests: security@gofindpart.com. A vulnerability report to the same address is acknowledged within 48 hours.