SOC 2
Operational security controls — security, availability, confidentiality, and processing integrity of customer data across the platform.
ALIGNED · TYPE II IN ROADMAPAI Image-to-Request
Snap a photo of any industrial part and our AI identifies it, pre-fills your request, and suggests the correct category.
Smart Part Matching
Our AI now suggests compatible alternatives and cross-references when your exact part is unavailable.
Faster Offer Matching
Improved seller notification waves now reach qualified suppliers up to 40% faster.
Industrial supply is where a wrong part costs a factory £60k an hour. The platform routing those orders needs to not flinch.
This page is the whole security posture — every control we run, the standards we're aligned to, and the gaps we're honest about. No certification-mongering. No theatre. A single page you can print.
Where the industry converges, so do we. These aren't certifications yet — they're the control frameworks our engineering & ops decisions are measured against internally, with an active roadmap to formal audit.
Operational security controls — security, availability, confidentiality, and processing integrity of customer data across the platform.
ALIGNED · TYPE II IN ROADMAPInternational standard for information security management systems — policy, risk assessment, and continuous improvement of controls.
ALIGNED · CERT. IN ROADMAPEU & UK GDPR compliance — lawful basis, data minimisation, subject-access, retention & deletion. Enforced at the platform level, not bolted on.
COMPLIANT · ONGOINGGoFindPart is not currently certified for SOC 2 or ISO 27001. These represent standards we design against and are actively working towards. We would rather tell you the true state of our security posture — and what we're doing to improve it — than sticker-badge a page and hope you don't look closely. Our roadmap to formal audit is below.
Six control groups. Every technical measure that runs on the platform, grouped by what it protects. No marketing categories, no fluff — these are the actual controls shipped in the codebase and infrastructure.
Security is a schedule, not a sticker. This is what's shipped today versus what we're executing against for the remainder of 2026.
If you've discovered a security vulnerability in GoFindPart — or even just something that looks off — we'd rather hear about it directly than read about it. Good-faith disclosure is protected, encouraged, and credited.
Procurement, infosec review, vendor questionnaire, pen-test summary request — we respond to all of it. No sales filter, no "schedule a call" wall.