Skip to content

How Goal Boss handles security

Every system Goal Boss builds or integrates is held to SOC 2 standards and penetration-tested before it goes live. Goal Boss does not perform SOC 2 audits, which stay with the company's auditor.

Will Pemble's background in hosted services and security goes back to Web.com, one of the largest web hosts on earth, which he built and sold.

Before a system goes live

Every build and every integration

  • An engineer reviews the code for security
  • Goal Boss runs a penetration test and fixes what it finds
  • Access is limited to the people who need it
  • The company has a written list of every outside service the system calls

What SOC 2 standards mean on a Goal Boss build

SOC 2 is the standard a company's auditor uses to test how a system protects data. Goal Boss builds each system to the same criteria, so the system can sit inside the company's own audit.

Access

People sign in through the company's own identity provider where it has one. Each person sees only what their role needs, and nobody shares a login.

Encryption

Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Passwords, keys and tokens are kept out of the code.

Audit trail

The system records who did what and when, so the company can answer a client's or a regulator's question about any record.

Change control

Every change is kept in version control and tested before release. The company holds the repository.

Backups

Backups are encrypted, and a restore is tested before the system goes live.

Outside services

The company gets a written list of every outside service the system calls, including each AI provider, and what data each one receives.

Company data and AI models

The company owns every system Goal Boss builds for it. The system runs in the company's own environment unless the company asks for something else.

Company data is not used to train AI models. Goal Boss uses AI providers whose commercial terms rule that out, or a model that runs inside the company's own environment.

Goal Boss signs a confidentiality agreement before it sees any company data.

The company's experts review what a system produces and stay accountable for it. Nothing Goal Boss builds reads sentiment or infers emotion from an employee.

The review and the test

Before release

Security review of the code

In Veracode's 2025 test, generative AI models chose the insecure way to write code 45% of the time when a secure way was available. Code written with AI on a Goal Boss build gets an engineer's security review before it ships.

Veracode, 2025 GenAI Code Security Report, July 30, 2025

Before go-live

Penetration test

Goal Boss attacks the system as an outsider and as a logged-in user. The test covers sign-in, access between accounts, input handling, the connections to the company's other software, and anything the AI model can be talked into doing that it should not. Findings are fixed and retested, and the company receives the results in writing.

When the company buys a product

Bought products

Goal Boss reads the vendor's SOC 2 report and security documentation before it recommends a product. The penetration test covers what Goal Boss configures and connects: the integration, the accounts and the permissions. The product itself stays the vendor's responsibility.

Questions about security

Does Goal Boss have a SOC 2 report of its own?
Goal Boss is a services practice and holds no SOC 2 report of its own. It builds each system to SOC 2 standards so that the system can be covered by the company's own audit.
Does Goal Boss perform SOC 2 audits?
Goal Boss does not perform SOC 2 audits or issue SOC 2 reports. An audit stays with the company's auditor.
Is company data used to train AI models?
Company data is not used to train AI models. Goal Boss uses AI providers whose commercial terms rule that out, or a model that runs inside the company's own environment.
Who owns the system, and where does it run?
The company owns every system Goal Boss builds for it. The system runs in the company's own environment unless the company asks for something else.
Can the company's security team review the work?
The company holds the code repository, and its security team can review the code and the test results at any point in the sprint.
Is the penetration test independent?
The test is Goal Boss's own. A company that needs an independent test can bring in its own tester, and Goal Boss will work with them.

Send your security questionnaire

If your company has a vendor security questionnaire, send it. Goal Boss answers it before any work starts.

© 2026 Goal Boss. All rights reserved.