- Q01Has Bubble ever supported SOC 2?
- Yes — uniquely among the standards we cover, Bubble holds a SOC 2 Type II report for the Security category, audited by Sensiba LLP. Their manual is explicit that the report covers the platform, not your app, and that the compliance doesn't automatically transfer. So Bubble has it; your app still needs its own examination.
- Q02Will an auditor accept Bubble's report as a sub-service organisation?
- Yes, that's exactly how it works. Your auditor treats Bubble as a sub-service organisation, inherits the platform controls in scope of Bubble's report, and tests the complementary user-entity controls you're responsible for — access management, privacy rules, change management. You'll need a current Bubble report; pull it through Bubble Sales before kickoff.
- Q03Can I do this without rebuilding off Bubble?
- For SOC 2 alone, yes. This is the one standard in the cluster where staying on Bubble is the recommended path. Inherit Bubble's platform controls, engage a CPA firm, run a 3–12 month observation window. Pre-A and Series A B2B SaaS regularly close enterprise deals on this exact path without ever leaving Bubble.
- Q04How long does a Type II audit actually take?
- Plan for two windows. Readiness — gap assessment, control design, evidence collection — runs 6–12 weeks. Then the audit observation period itself is 3 months for the shortest viable Type II, 6 months for what most enterprise buyers prefer, 12 months for full-cycle. Pick the window your earliest enterprise deal requires.
- Q05Does SOC 2 also satisfy ISO 27001 or HIPAA?
- It aligns with ISO 27001 — roughly 70% control overlap — but ISO is a certification of an information-security management system, not an attestation of controls. EU and UK buyers often demand the ISO certificate alongside SOC 2. HIPAA is unrelated: SOC 2 is voluntary and contractual, HIPAA is statutory and Bubble explicitly declines BAAs.
- Q06Can Bubble sign a DPA or BAA for SOC 2 purposes?
- Bubble signs a GDPR-compliant DPA covering personal data of end users with Standard Contractual Clauses and the EU-US Data Privacy Framework. They do not sign BAAs. For SOC 2 purposes the DPA is enough; you reference it as the contract with your sub-service organisation in your system description.
- Q07What about plugins — do they break SOC 2?
- Plugins aren't covered by Bubble's SOC 2 audit. Your auditor will treat each privileged plugin as a vendor you have to manage. Keep an inventory, document why each plugin is necessary, monitor what data it touches. The minor severity entry above isn't "don't use plugins" — it's "document them as part of your control environment."