Skip to main content

Compliance FAQ

J
Written by Joe Banks

Has RiffleCM been independently assessed?

Yes. RiffleCM passes the Cloud Application Security Assessment (CASA) annually. CASA is administered by the App Defense Alliance and required by Google for any application that accesses Gmail or Google Workspace data. It is based on the OWASP Application Security Verification Standard (ASVS) and is performed by a Google-authorized independent lab, which runs dynamic security testing against the live production application and verifies that no high-risk vulnerabilities are present.


Do you have SOC 2?

RiffleCM does not currently hold its own SOC 2 certification. Our core infrastructure providers maintain SOC 2 Type II and ISO 27001 certifications, and we build on their controls.


What third parties process customer data?

RiffleCM uses a small number of established vendors for cloud hosting, AI processing, email delivery, error monitoring, product analytics, customer support, and billing. Each acts under contract as our service provider, as described in section 4 of our Privacy Policy.

Did this answer your question?