Our office:
1495 Canyon Blvd
Suite 107
Boulder, CO 80302
info@centro.rocks

SOC 2 Type 2 audited since 2022. Independent penetration testing every year. Minimal data storage by design.
Centro has maintained SOC 2 Type 2 attestation since 2022. The most recent examination was performed by A-LIGN, covering August 1, 2024 to July 31, 2025, against the AICPA Trust Services Criteria for Security.
The auditor noted zero exceptions across all tested controls. The May 2025 third-party penetration test identified no critical or high-risk vulnerabilities. No security incidents occurred during the review period.
Re-certification runs every fall. The current audit is in progress. A third-party penetration test runs every spring.
The full report is available to customers and prospects under NDA on request.
Centro runs a serverless architecture on AWS.
Active-active deployment across three AWS regions, additional regions available on demand. Health checks fail traffic over automatically.
Monitoring runs on CloudWatch with automated alarms by region and component. Development, test, and production environments are logically separated. All changes are peer reviewed and deployed through git-based CD.
Encryption in transit: TLS 1.2 or higher, enforced and verified in the May 2025 penetration test.
Retention: application metadata backups are kept 7 days in AWS, then deleted automatically. Salesforce licensing backups are exported weekly and deleted automatically by Salesforce. Stored data is purged on a defined schedule, a control tested in the SOC 2 examination.
Customers can request deletion of their data at any time, and data is deleted at contract end.

CentroBot runs on the same audited Centro platform and infrastructure described above. Same regions, same encryption, same minimal-storage model.
CentroBot messages travel the standard Slack and Microsoft Graph message paths. There is no separate or ephemeral-only channel for business content.
Inference is performed via the OpenAI API. Prompts and grounding data are processed, not stored, by Centro.
Every API call Centro makes runs with the active user's own permissions via per-user OAuth 2.0.
"Centro respects any security or permission customized in Salesforce, Slack, or Microsoft Teams and never circumvents the policies configured in those platforms."
Refresh tokens are revocable at any time and stored encrypted.
Centro recommends least-permissive role assignment. Centro inherits whatever the customer configures.
Non-Salesforce-licensed users act through a governed automation user model with the same permission inheritance.
Firms subject to FINRA 4511 and SEC 17a-4 retain and supervise business communications through their existing archiving stack.
Because CentroBot and all Centro features deliver messages through the native Slack and Microsoft Graph message paths, communications are captured by the archiving and supervision tools the firm already runs, such as Global Relay or Smarsh. Centro does not create out-of-band channels that bypass capture.
Centro stores no message content itself, which keeps the customer's archive the single system of record.
Centro's architecture supports the customer's compliance program. The customer's compliance obligations remain their own.
Centro does not store PHI. Message content and Salesforce record data are never written to Centro's systems. PHI may transit Centro's infrastructure during processing, encrypted in transit with TLS 1.2 or higher.
Centro will sign a Business Associate Agreement on request.
Per-user OAuth means Centro can never read more than the requesting user is already authorized to see in Salesforce or the messaging platform.
Centro supports Salesforce Government Cloud.
Centro is not FedRAMP authorized.
AWS is Centro's sole subservice organization, as stated in the SOC 2 report.
A current list of third-party services is available on request.
Vendors and third parties are reviewed at onboarding and annually for compliance with Centro's security requirements, a control tested in the SOC 2 examination.
Centro has maintained SOC 2 Type 2 attestation since 2022, audited annually by A-LIGN against the Security Trust Services Criteria. The most recent report covers August 2024 through July 2025 with zero exceptions. Request the report under NDA.
No. Centro stores license data, encrypted refresh tokens, and activity metadata only. Message content and Salesforce record data are never stored.
Yes. All API calls run with the individual user's own permissions through per-user OAuth 2.0, all traffic is encrypted with TLS 1.2 or higher, and Centro's SOC 2 Type 2 controls are audited annually. Centro never circumvents permissions configured in Salesforce, Teams, or Slack.
Yes. CentroBot sends and receives messages through the standard Slack and Microsoft Graph message paths, so your existing archiving and supervision tools capture them automatically.
Centro runs active-active across AWS Ohio, Oregon, and Paris regions.
Yes, on request. Centro does not store PHI, which keeps the data footprint minimal, and a BAA is available for covered entities that require one.
Application metadata backups are deleted automatically after 7 days. Stored data is purged on a defined schedule. Deletion on request and deletion at contract end are both supported.