Data classification
Customer Content
Customer content is data created by or belonging to your customers — documents, messages, user-generated content, configurations, and business data stored in your product. SaaS vendors with access to your product data store carry this risk.
Risk profile
Unauthorized access to customer content can violate contractual confidentiality obligations, trigger data breach notification requirements, and destroy customer trust. Vendors with access to customer content should be assessed at the same level as your own internal systems.
Common questions
Is customer content covered by my SOC 2 audit scope?
If your SOC 2 covers the systems that store customer content, then yes — but verify the system description in Section I to confirm scope. Infrastructure-level vendors (AWS, GCP) are typically listed as subprocessors, not in scope themselves.
Which of your vendors handle Customer Content?
TrustVendor tracks data class exposure across your entire vendor portfolio and computes residual risk per relationship.
Book a demo