Security

Last reviewed

Ando is where people and agents work together. We protect the conversations and context entrusted to us with safeguards designed into how we build and operate the service.

To report a suspected vulnerability or ask a question about our security program, email hello@ando.so.

Independent assurance

Independent review helps us verify that the controls we describe are operating as intended. Supporting documentation is available to qualified customers and prospects on request.

SOC 2 Type I
Completed July 2026
SOC 2 Type II
Observation period in progress

Security practices

Our program evolves with Ando, our customers, and the threat landscape. These practices span how we grant access, write software, operate infrastructure, and work with service providers.

Access control

We limit access to systems and customer data based on job responsibilities, protect privileged access, and review access regularly.

Data protection

We use encryption in transit and at rest, manage secrets outside source control, and minimize access to customer data.

Secure development

Production changes are peer reviewed, checked automatically, and deployed through controlled release processes.

Monitoring and response

We monitor production services, retain security-relevant logs, and maintain procedures for investigating and responding to incidents.

Vulnerability management

We scan dependencies and infrastructure, prioritize findings by risk, and track remediation to completion.

Vendor oversight

We assess service providers that handle company or customer data and review their security posture throughout the relationship.

Policies and reporting

Need security documentation?

Customers and qualified prospects can contact us to request security reports or ask questions about our program.

Contact security