Back

Back

Company News

How Cubby Keeps Your Facility's Data Safe (and What a SOC 2 Audit Actually Means)

Matt Engfer | Cubby

Cubby Team

・

Share:

Cubby's data security policy

Cubby has completed an independent SOC 2 security audit. If that phrase means nothing to you, you're in good company; it means nothing to most storage operators, which is exactly why we wrote this post. Here's what the audit found, what it means for your data, and how Cubby protects your business, in plain English.

Security Is Your Business. It’s Ours Too.

When you run a self-storage facility, security isn't an abstraction. You think about gates, cameras, locks, and lighting every day. Keeping things safe is what your customers are paying you for.

Choosing a facility management platform is one more, crucial piece of that security effort. Your tenants' records, payment activity, and personal details will live in your software vendor's system. With data breaches making headlines regularly, you should hold that vendor to the same standard you hold yourself. Here's how Cubby measures up.

The SOC 2 Audit, Defined

A SOC 2 audit is a rigorous, standardized examination in which licensed auditors evaluate a company's security controls against 

Cubby completed a SOC 2 examination covering the Security category of the Trust Services Criteria. An independent auditing firm examined our systems, policies, and safeguards, then issued its report evaluating the design of our controls. The auditor's opinion: our security controls are suitably designed to protect the systems and data our customers entrust to us. In other words, the controls described below aren't marketing copy; they were documented, inspected, and evaluated by outside auditors whose professional obligation is to accuracy, not to making us look good.

Cubby security at a glance

Safeguard

What it means for your data

Independent audit

SOC 2 examination (Security category) covering the design of our controls.

Infrastructure

Hosted on Google Cloud Platform, with enterprise-grade physical security, redundancy, and environmental protections.

Encryption

Customer data is encrypted in transit over public networks and encrypted at rest in Google Cloud.

Access control

Role-based access on a least-privilege basis, multi-factor authentication for production systems, documented approval for access requests, recurring access reviews, and prompt revocation when someone leaves.

People

Background checks as part of hiring, confidentiality agreements, and security training at onboarding and regularly thereafter.

Monitoring and testing

Continuous monitoring with automated alerting, dependency scanning for known vulnerabilities, and penetration testing by outside specialists.

Incident response

A documented incident response plan, tested regularly. If an incident affects you, we tell you, and keep you informed until it's resolved.

Business continuity

A documented disaster recovery plan, which we test regularly.

How Your Data is Protected

Cubby runs on Google Cloud Platform, the same infrastructure that powers Gmail and Google Search, so your data lives in Google's hardened data centers, protected by layered physical security and encrypted at rest. Whenever your data travels over public networks (a tenant paying online, a manager logging in from home), it's encrypted in transit, so it can't be read if intercepted.

Our production environment sits behind a web application firewall, and the network is segmented into isolated zones so customer data isn't reachable from systems that don't need it. Think of it as the digital equivalent of individually locked units inside a gated facility.

Who Can Touch Your Data

Most breaches start with access: a stolen password, an over-privileged account, a departed employee whose login was never shut off. Cubby's access controls are built around least privilege: we assign access by role, so people get only what their job requires. Reaching production infrastructure takes multi-factor authentication, and access requests go through a documented approval process. We review who has access to what on a regular basis. And when someone leaves Cubby, their access goes with them.

The people-side matters too. We run background checks as part of hiring, employees sign a confidentiality agreement covering customer data, and we train people on security when they join and again on a regular basis.

Always Watching, Always Testing

Strong walls aren't enough; someone has to watch them. We monitor our systems continuously, with automated alerts that flag unusual activity for immediate investigation, not discovery weeks later.

We also hunt for weaknesses before attackers can find them. We scan our code dependencies for known vulnerabilities, patch infrastructure as part of routine maintenance, and bring in outside specialists for penetration testing: a controlled, simulated attack on our own systems. What we find, we fix, the worst first. And it's all accountable at the top: a risk committee oversees our security program, supported by regular company-wide risk assessments.

If Something Goes Wrong

No honest company will tell you a cyber attack is impossible. What separates prepared companies from headline-making ones is what happens next. Cubby maintains a documented incident response plan that defines, in advance, how we detect, contain, and recover from security incidents. And we test that plan regularly, because a plan you've never tested is just a document.

If an incident ever affects you, you'll hear it from us, and we'll keep you informed until it's resolved. A documented disaster recovery plan, which we also test regularly, keeps critical services running through disruptions of any kind.

Ask Us the Hard Questions

Your data is the operating history of your business, and you deserve to know exactly how it will be protected before you send anyone a single record. We welcome the scrutiny. Talk to a Cubby representative to go deeper (including reviewing our full SOC 2 audit report) at cubbystorage.com.

Join the operators making the switch

Join the operators making the switch

Join the operators making the switch