Added formal security disclosures including SOC 2 Type II certification, MFA requirements, production access controls, and vulnerability program.
Why it matters: The updated document establishes formal security commitments previously absent from public Windsurf documentation. By disclosing SOC 2 Type II certification, encryption practices, access controls, and employee security requirements, Windsurf creates a documented baseline against which procurement teams and compliance officers can evaluate the platform's data protection measures. This materialization of security practices may reduce vendor assessment friction for organizations subject to GDPR, CCPA, or internal data protection governance.
Adds formal data protection complaint procedures and regulatory escalation rights for UK users and all applicable jurisdictions
Why it matters: The updated terms establish clear procedural pathways for users to file data protection complaints and explicitly confirm rights to escalate to regulatory authorities. This clarifies dispute resolution procedures and regulatory recourse that apply under UK and EU data protection law, potentially reducing ambiguity around how Eventbrite handles privacy complaints.