incident.io security review: SOC 2, AI training & subprocessors

What incident.io publishes about its security, privacy and use of your data, with a link to the page each fact came from. Checked October 10, 2026.

Transparency score
85/100
SOC 2
SOC 2 Type II
ISO 27001
Not mentioned
Trains AI on your data?
Not found
Subprocessors
20 listed

"Not found" means our reader didn't find it on the public pages it could read; the vendor may still publish it.

Does incident.io train AI on your data?

Our reader didn't find a statement about training AI models on customer data on the incident.io pages it could read. incident.io may publish one elsewhere, for example in a help center, AI terms or a trust portal. Ask the vendor in writing and check its DPA and AI terms.

Certifications incident.io claims

Certification or reportMentioned on
SOC 2 Type IIincident.io/legal/data-processing-addendum
SOC 2 Type Iincident.io/security
HIPAAincident.io/legal/data-processing-addendum
HITRUSTincident.io/legal/data-processing-addendum

Privacy laws and frameworks mentioned: GDPR, CCPA/CPRA. These are laws the vendor says it follows, not certifications.

A certification on a website is a claim. For anything sensitive, ask incident.io for the SOC 2 report or ISO certificate.

incident.io subprocessors

incident.io lists 20 subprocessors on incident.io/legal/sub-processors:

Security features mentioned

SSO / SAMLMentioned
SCIM provisioningMentioned
Multi-factor authenticationMentioned
Encryption at restMentioned
Encryption in transitNot found
Penetration testingMentioned
Bug bounty / disclosure programMentioned
Audit logsNot found
Data residencyNot found
security.txt contactmailto:security@incident.io

Key documents

Trust / security centerincident.io/security
Privacy policyincident.io/legal/privacy
Subprocessor listincident.io/legal/sub-processors
Data processing agreement (DPA)incident.io/legal/data-processing-addendum
AI policyNot found
TermsNot found
Status pagestatus.incident.io

How this score is worked out

CheckPointsResult
Security or trust page15Yes
Certifications listed20Yes
Privacy policy10Yes
Subprocessor list15Yes
DPA available10Yes
AI training policy stated15No
security.txt contact5Yes
Status page10Yes

The score measures how much of a standard security review our reader could answer from incident.io's public pages. It is not a rating of how secure incident.io is, and a "No" can mean the document exists where our reader couldn't see it.

Check another vendor

Get the same profile for any vendor in seconds, or let your AI agent do it with Stormap's free MCP server.

Other Developer & data vendors

Airbyte · Algolia · Amplitude · Auth0 · CircleCI · Clerk · Cloudflare · Confluent · Databricks · Datadog · DigitalOcean · Fastly

Source: incident.io's own public website (5 pages read on October 10, 2026). Stormap is not affiliated with incident.io. Facts are what the vendor publishes about itself; certifications are claims, not verified audit reports. Something wrong or out of date? Pages are re-checked every two weeks.