Trust Center

Independent assurance over the security, availability and confidentiality of every Thinfinity deployment.

Trust Center
AICPA SOC 3 Report now available

AICPA SOC 3 Report now available

Examination period March 1, 2025 to February 28, 2026
Issued by Thoropass Assurance, Arlington, VA

Security
Availability
Confidentiality

Three Trust Services Criteria, independently examined

Cybele Software's controls were evaluated against the AICPA's 2017 Trust Services Criteria for Security, Availability, and Confidentiality throughout the entire 12-month examination period.

Security

Cybele protects customer data from security breaches through technological controls.

Identity & access management
Encryption standards
Network security and segmentation
Threat & vulnerability management
Security monitoring and reporting

Availability

Thinfinity Products are kept available and recoverable through tested operational controls.

Business continuity & DR procedures
Capacity and performance management
Data backup, recovery, and replication
System and infrastructure monitoring
Incident response procedures

Confidentiality

Confidential customer data is classified, encrypted, and disclosed only when authorized.

Data classification policy
Encryption of confidential data
Data retention and secure disposal
Information sharing standards
Confidentiality commitments in MSA

Audited at the Cybele control plane

These attestations apply to Cybele Software's own organization — our development, build, deployment, and support processes for the Thinfinity Products.

SOC 2 Type II

Operational effectiveness audit

Confidential, detailed report under NDA. Available to enterprise customers and prospects on request.

Security · Availability · Confidentiality
12-month examination period
Detailed control descriptions and test results
NDA required for distribution

SOC 3

Public attestation report

Freely distributable summary. No NDA required. Use it in your RFP responses and vendor questionnaires.

Same TSC scope as SOC 2 Type II
March 1, 2025 → February 28, 2026
Auditor's opinion + management assertion
Public — share with anyone
Oracle

Cloud Build Partner

Marketplace listed, Co-sell ready

Oracle Cloud Infrastructure

Our primary cloud platform. Thinfinity is offered through the Oracle Cloud Marketplace and runs natively on OCI compute, networking, and Kubernetes (OKE) across global regions.

SOC 1

Financial controls

SOC 2 Type 2

Trust Services Criteria

SOC 3

Public attestation

ISO 27001

Information Security Management

ISO 27017

Cloud security controls

ISO 27018

Cloud PII protection

PCI DSS

Payment card data

HIPAA

U.S. health data

FedRAMP

U.S. federal cloud

GDPR

EU data protection

BSI C5

German cloud security

CSA STAR

Cloud Security Alliance

IONOS

Technology Partner

EU sovereign cloud, No CLOUD Act exposure

IONOS CLOUD

Our European sovereignty partner. German-headquartered, GDPR-native, operated entirely within EU jurisdiction. Recommended for customers with EU data residency and digital sovereignty requirements.

ISO 27001

Information Security Management System certification for IONOS data centers

BSI C5 (Type 1)

Germany's Cloud Computing Compliance Criteria Catalogue for Compute Engine, Cloud Cubes, S3

BSI IT-Grundschutz

German federal IT baseline protection — first cloud provider to hold both this and C5

GDPR

EU General Data Protection Regulation — data processed and stored entirely within the EU

PCI DSS

Payment Card Industry Data Security Standard support for hosted environments

ISO 27017 / 27018

Cloud-specific information security and PII protection in the cloud

Microsoft Azure

Subservice Organization

Microsoft Azure

Named as a subservice organization in our SOC 3 report. Azure provides infrastructure and data hosting services that support Cybele's own development, build, and deployment environment for the Thinfinity Products.

SOC 1

Financial controls

SOC 2 Type 2

Trust Services Criteria

SOC 3

Public attestation

ISO 27001

Information Security Management

ISO 27701

Privacy Information Management

ISO 27017

Cloud security controls

ISO 27018

Cloud PII protection

PCI DSS

Payment card data

HIPAA / HITRUST

U.S. health data

FedRAMP High

U.S. federal cloud

GDPR

EU data protection

BSI C5

German cloud security

What you get, by responsibility layer

Thinfinity is customer-deployed: you keep control of where it runs and what data it touches. Compliance is built up in three layers.

What you get, by responsibility layer

Customer-managed

User access policies
Data residency choices
Network segmentation
Configuration & hardening

Cybele-attested · SOC 2 Type II + SOC 3

Secure SDLC
Identity & access management
Encryption in transit
Incident response & monitoring

Provider-attested · OCI or IONOS

Physical data center security
Encryption at rest
Compute & storage availability
Patching of managed services

Need the full report?

Three ways to get what you need for vendor reviews, RFPs, and procurement.

Download the SOC 3 report

Public attestation. No NDA required.

Request the SOC 2 Type II

Detailed audit report under mutual NDA. Routed through your account team.

Talk to compliance

Vendor questionnaires, custom scoping, or on-prem deployment review.