SOC 2 Type II
Buena's control environment is independently examined under the SOC 2 Type II framework.
Review in the Trust CenterTrust & security
Give security and procurement a clear view of Buena's assurance, privacy practices, access controls, and supporting documentation.
Enterprise assurance
A concise register of current assurance, privacy, identity, and enterprise access positions—with a direct route to supporting evidence.
Buena's control environment is independently examined under the SOC 2 Type II framework.
Review in the Trust CenterBuena maintains privacy practices designed to support GDPR-compliant processing.
Enterprise authentication is available through supported SSO and SAML configurations.
Workspace access can be scoped by role so people see and control the work appropriate to them.
Enterprise customers receive dedicated support through evaluation, rollout, and operation.
Product controls
Boundaries sit inside the workflow, so teams can see what is eligible, what requires review, and what happened next.
Require a person to review consequential work, including a first touch, before it moves into execution.
Person in the loopKeep customers, partners, open opportunities, and other protected groups outside eligible workflows.
Eligibility evaluatedDefine the channels, local operating hours, and account rules that a workflow must respect.
Policy checkedKeep the evidence, policy checks, review state, and resulting activity visible to the team.
Visible to the teamData protection
The privacy policy describes encryption in transit (TLS/SSL) and at rest, alongside access controls and authentication.
Access controls and authentication are paired with need-to-know access for authorized personnel.
Security assessment, secure development practices, and incident-response procedures form part of the operating approach.
Service providers processing data on Buena's behalf operate under data processing agreements and appropriate safeguards.
Responsible automation
Match autonomy to consequence, evidence quality, and the controls around execution.
Keep the triggering change and account context beside the recommendation so a person can inspect the basis for action.
Automate bounded preparation work first, then retain review where a decision affects an account or external communication.
Use accepted, rejected, edited, and disqualified work to refine the workflow rather than expanding activity by default.
Security review
Review current compliance status, supporting documentation, and control details in the Buena Trust Center. Product configuration is confirmed against your intended workflow during evaluation.
Ask a data protection questionBring the data, access, deployment, review, and procurement requirements that matter to your organization.
Map where data enters, which decisions Buena supports, and which actions remain gated by your team.
Agree the available controls and documentation for the specific product scope before deployment.