Since Descript was founded, we’ve treated the security, confidentiality, and privacy of our users’ data with the utmost care. We know that the data our users share with us ranges from the personal to the proprietary, and we take our responsibility to protect that data very seriously.
Today, we’re proud to announce that we are SOC 2 Type I compliant, and we expect to be SOC 2 Type II compliant in 2021. That means that the integrity of the systems we have in place to protect our users’ data has been verified by an independent auditor, and we will continue to conduct these audits regularly.
“Descript’s systems and security are trusted by companies such as The New York Times, HubSpot, NPR, and Al Jazeera,” says Jay LeBoeuf, Descript’s Head of Business Development. “Our SOC 2 certification and Single Sign-On (SSO) support now allows Enterprise clients to rapidly integrate Descript into their existing teams and workflows.”
SOC stands for Systems and Organizations Controls, and it refers to a series of reports produced and administered by the American Institute of Certified Public Accountants (AICPA) during an audit of an organization like Descript. SOC 2 specifically covers controls relevant to security, availability, processing integrity, confidentiality, and privacy. Together, these overlapping concerns ensure your data is adequately protected within the organizations you share it with.
“The privacy, confidentiality, and security of our users’ data has been a top priority for us since day one, and a lot of the work that we’ve done over the past year to achieve SOC 2 compliance has been formalizing internal policies and automating security controls to help us scale this culture as we grow the company,” says Sunny Rochiramani, Vice President of Engineering at Descript.
SOC 2 Type I confirms compliance at a specific point in time: In Descript’s case, December 15, 2020. SOC 2 Type II confirms continued compliance six months after Type I, and we expect to certify this compliance later in 2021.
Because of the work we had already done to protect our users’ privacy and the security of their data, attaining SOC 2 Type I compliance was primarily about codifying policies already in place and automating security reviews.
Some of the work we did to earn SOC 2 Type I compliance was:
For detailed information, visit our Security and Confidentiality page, which contains an overview of Descript’s data security and confidentiality systems. In a nutshell: Your Project data — the files you upload to Descript, the transcripts of those files, and other associated metadata — are confidential, even from Descript, and if you delete your data, we permanently delete it from our servers.
Our SOC 2 report is only available to our Enterprise clients. Please visit our Pricing page to discover the features of Descript Enterprise accounts, and contact us to learn more about becoming an Enterprise client.