Compliance & Trust
InboxIssue runs on DuoCircle's compliance program.
InboxIssue is built and operated by DuoCircle LLC. The InboxIssue service line is in scope for our SOC 2 Type II examination and inherits DuoCircle's CSA STAR posture. All vendor-assessment documents are published in one place at the DuoCircle Trust Center.
SOC 2 Type II
Annual examination since 2022 by Hancock Askew & Co, LLP. All four Trust Services Criteria: Security, Availability, Confidentiality, Processing Integrity. Report available under Bonterms Mutual NDA.
CSA STAR Level 1
InboxIssue inherits the DuoCircle organizational entry in the Cloud Security Alliance public registry. CAIQ Lite, subset of CCM v4.1. Renewed annually.
View DuoCircle on CSA STAR →HECVAT Full
For colleges and universities, the Higher Education Community Vendor Assessment Toolkit, current version, available under NDA.
Penetration testing
Annual third-party penetration test. Executive summary available under NDA.
Need the SOC 2, HECVAT, or our policy pack?
Submit one request through the DuoCircle Trust Center. We use the standardized Bonterms Mutual NDA, published in advance so your legal team can review it before any conversation begins. We respond within one business day, and most often the same day.
Public, no NDA
- DuoCircle CSA STAR registry entry
- Security Overview, plain-English version of our control set.
- Policy catalog, the titles and review cadence of every policy in our information security program.
- Subprocessor list, every third-party vendor that processes personal data on our behalf.
- Bonterms Mutual NDA, published in advance so you can read it before you ask.
InboxIssue runs on the standardized Bonterms Cloud Terms. Self-serve plans run on Bonterms Online Cloud Terms, accepted at sign-up. Enterprise plans run on a counter-signed Cover Page. Same balanced framework either way, no surprise additions.
Reviewed 2026-05-06.
See also: Privacy Policy · Cloud Terms · DPA