Security and Privacy at LBC

The Last Business Card is SOC 2 Type II Compliant

We are proud to demonstrate our ongoing commitment to data security and privacy through our SOC 2 Type II compliance. This certification affirms that our systems and processes meet rigorous standards for safeguarding customer information. Security, availability, and confidentiality are core to our platform, and this milestone reflects our dedication to maintaining a trustworthy and compliant environment for every organization we serve.


A Secure and Sustainable Solution for Modern Networking

The Last Business Card (LBC) platform offers enterprises a secure, sustainable solution for professional networking and contact management. Users can share contact details via NFC-enabled smart cards, QR codes, and branded digital landing pages, while also capturing recipient information in return—supporting true two-way relationship building.

Unlike traditional business card platforms that simply push static contact details into a recipient’s address book, LBC initiates a mutual exchange:


Built with Data Minimization and Enterprise Integration in Mind

A key architectural principle of LBC is data minimization. Rather than persisting sensitive corporate directory data in our infrastructure, LBC connects directly to a customer’s authoritative identity source—such as Microsoft Active Directory or Entra ID—and renders contact details dynamically. This ensures:


Enterprise-Grade Capabilities

LBC also provides:

The platform is delivered via a secure SaaS architecture hosted on AWS, with end-user access available on both web and mobile.

Compliance

AICPA SOC 2 badge SOC 2

Controls

View all
Infrastructure security
  • Encryption key access restricted
  • Firewall access restricted
  • Unique network system authentication enforced
View 3 more Infrastructure security controls
Organizational security
  • Asset disposal procedures utilized
  • Portable media encrypted
  • Anti-malware technology utilized
View 9 more Organizational security controls
Product security
  • Data encryption utilized
  • Control self-assessments conducted
  • Vulnerability and system monitoring procedures established
Internal security procedures
  • Continuity and Disaster Recovery plans established
  • Continuity and Disaster Recovery plans tested
  • Cybersecurity insurance maintained
View 23 more Internal security procedures controls
Data and privacy
  • Data retention procedures established
  • Customer data deleted upon leaving
  • Data classification policy established