Cactus Trust Center

Review Cactus’s security controls, SOC 2 report status, and subprocessors, and find the policies covering personal information and processing terms.

Security controls

The Trust Center groups its controls by SOC 2 category. This information was checked on September 26, 2026.

CategoryPublished controls
SecuritySign-in uses Google or GitHub, with no passwords. Session cookies are inaccessible to page scripts, use HTTPS, and expire after a week without use. Only Owners can make specified membership and product changes, and the server checks their role. The GitHub App is read-only. AI-client tokens last an hour and are stored as hashes. Other controls cover two-factor authentication for Cactus’s GitHub organization, signed-message checks, cross-site request protection, rate limits, HTTPS and encryption, logging, pull requests and checks, deploys, and locked dependencies. Anyone can report a security problem without an account.
AvailabilityThe website, app, and Help Centers use a distributed network. Jobs can resume after an interruption, up to six hours of database history is retained, and repository copies and the search index can be rebuilt from GitHub.
ConfidentialityVisitors see eligible pages set to Everyone, and answers to visitors don’t list code files as sources. Code searches run in an isolated environment without network access and can’t change stored copies. Cactus’s answering system doesn’t write code to disk. Other controls cover secret scanning and removal, Slack secret replacement, and deletion of a product’s data and code copies.
Processing integrityPushes are checked against GitHub’s signature. Changed page sections are saved as new versions.
PrivacyFor personal-information practices, read the [Privacy Policy](concept://cactus-privacy-policy). For contractual processing terms, read the [Data Processing Addendum](concept://cactus-data-processing-addendum).

SOC 2 status

No. The Trust Center lists both SOC 2 Type I and Type II reports as Being prepared. Type I is an independent auditor’s report on control design; Type II covers how controls work over a period of months.

Subprocessors

The Trust Center’s Companies section lists each company’s name, location when available, what it does for Cactus, and what it receives. You’ll also find the same companies in the Privacy Policy and Data Processing Addendum.

Read the Trust Center

Open /security on heycactus.ai to read the Trust Center.

Related pages