SOAR

Security at SOAR

Last updated August 24, 2026

This page is written for the person at your company who has to sign off on letting SOAR touch your data. It describes what the system actually does, and it is equally clear about what we do not have.

If you need something more formal — a completed security questionnaire, a walk-through with whoever wrote the code — email hello@soar-crm.com and ask.


What we do not have

Putting this first, because every vendor page buries it.

We run our own adversarial test suite against the application, described below. That is our own work testing our own code, and it is not independent assurance. It is useful to us and it is honest to show it to you, but it is not a pentest report and we will never describe it as one.

If a third-party report is a hard requirement for your procurement process, say so early. We would rather tell you where we are than have you find out three weeks into a purchase.

Why none of this is claimed anywhere else on our site: a security claim you cannot evidence is worse than a gap you disclosed. Overstating security in a published policy is an unfair-or-deceptive practice under Section 5 of the FTC Act, and it is enforced.


What we do have

Every item here corresponds to something in the running system.

Getting in

Keeping tenants apart

Data in transit and at rest

The application itself

Who at SOAR can see your workspace

Stated plainly because you should not find it out later:

SOAR staff can open your workspace as an administrator in order to configure, train and support your agents. That access is time-limited, requires a written reason, and every action is logged. Those logs are kept for three years — deliberately longer than anything else we retain, because an audit trail that expires before the audit is not an audit.

We will show you your own access log on request.

Artificial intelligence

Before each release

An adversarial test suite runs against a local instance on a test database — never production. It covers authentication bypasses, tenant isolation, injection and payload handling. A failure there is treated as a security regression that blocks the release, not as a broken test to be skipped.


Known gaps we are working on

Listed because you will find them anyway, and because a vendor who tells you first is the one worth trusting.


Reporting a vulnerability

Email hello@soar-crm.com. Tell us what you found and how to reproduce it.

We will acknowledge within two business days and keep you updated until it is resolved. We will not pursue good-faith research that stops at proof and does not access, alter or exfiltrate anyone else's data. We do not currently pay a bounty, and we will credit you if you would like us to.

Please do not run scans or penetration tests against the service without asking first — see §4 of the Acceptable Use Policy. Ask; the answer is usually yes, in a scheduled window.


Related

SOAR CRM LLC · 100 Holly Park Court, Holly Springs, GA 30115 · hello@soar-crm.com