Legal · Last updated June 1, 2026
Security at Bobbuilt
Bobbuilt handles regulated, high-value data on behalf of life insurance agencies. Security is built into how we design, ship, and operate the platform — not bolted on. This page summarizes our program. For deeper diligence, request our SOC 2 Type II report and security questionnaire under NDA.
Infrastructure
- Hosted on SOC 2 audited cloud providers in the United States
- Logical isolation between customer environments
- TLS 1.2+ enforced for all data in transit, including internal service-to-service traffic
- AES-256 encryption at rest for databases, object storage, and backups
- Regional data isolation available for enterprise customers
- Network segmentation with private subnets and zero public ingress to data stores
Identity and access
- Role-based access controls with least-privilege defaults
- Mandatory MFA for all employee access to production and supporting systems
- Single sign-on (SAML, OIDC) available for customer accounts on enterprise plans
- Just-in-time access for production with full session recording and approval workflows
- Automated provisioning and deprovisioning tied to HRIS
Application security
- Mandatory peer code review on every change
- Static analysis, dependency scanning, and secret scanning on every pull request
- Threat modeling for new features that touch authentication, billing, or PII
- Annual third-party penetration test; remediation tracked to closure
- Public bug bounty for in-scope assets — contact the contact form at bobbuilt.io/contact for scope
Monitoring and incident response
- Centralized audit logging across the platform and admin tooling
- 24/7 on-call rotation with documented severity ladders
- Documented incident response plan exercised at least annually
- Customer notification within 72 hours of a confirmed Personal Data Breach affecting their data
- Post-incident reviews shared with affected customers
Business continuity
- Automated backups with point-in-time recovery for primary datastores
- Multi-AZ redundancy for production workloads
- Documented RTO of 4 hours and RPO of 1 hour for tier-1 services
- Annual disaster recovery test with documented outcomes
People and vendors
- Background checks for personnel with production access, where permitted by law
- Mandatory annual security and privacy training, with role-specific training for engineering
- Vendor risk reviews before granting access to customer data
- Written DPAs and SCCs in place with all subprocessors that handle Personal Data
Compliance
- SOC 2 Type II — annual audit
- GDPR / UK GDPR aligned (see DPA)
- CCPA / CPRA aligned
- TCPA and DNC tooling built into the platform
- HIPAA BAA available on request for qualifying engagements
Responsible disclosure
We take vulnerability reports seriously. Email the contact form at bobbuilt.io/contact with reproduction steps and any relevant context. We acknowledge reports within one business day, validate within five business days, and keep researchers updated through remediation. Please do not test against customer accounts you do not own, and do not exfiltrate data beyond what is necessary to demonstrate the issue.
Request documentation
Customers and qualified prospects can request our SOC 2 report, penetration test summary, security questionnaire, subprocessor list, and architecture overview by emailing the contact form at bobbuilt.io/contact from a corporate domain.
Ready to build your book?
Talk with our team about how Bobbuilt fits your agency.
Book a 30-minute call