Skip to main content

attestation

SOC 2 evidence across 27 vendors

SOC 2 is an attestation report, not a certification. A CPA firm examines controls against the AICPA trust services criteria and issues a restricted-use report for a period. CertReports indexes what is public: the report type, period and auditor where the vendor or a registry states them, plus the CSA STAR Level 2 attestations built on SOC 2 examinations.

Verified rows
0
Vendor-stated
27
Expired
0
Last verified
17 Sep 2026
Vanta logo

Vanta

Compliance and GRC

Vanta—the proven leader in automated compliance helping startups…

SOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedPCI DSS mark, CertReports state Vendor-statedISO 27001 mark, CertReports state Vendor-statedCSA STAR mark, CertReports state Verified
3 verified · 9 stated17 Sep 2026
CrowdStrike logo

CrowdStrike

Security

SOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedPCI DSS mark, CertReports state Vendor-statedISO 27001 mark, CertReports state Vendor-statedCSA STAR mark, CertReports state Verified
3 verified · 12 stated17 Sep 2026
Datadog logo

Datadog

DevOps and observability

HIPAA mark, CertReports state Vendor-statedSOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedPCI DSS mark, CertReports state Vendor-statedISO 27001 mark, CertReports state Vendor-stated
3 verified · 13 stated17 Sep 2026
Snowflake logo

Snowflake

Data platforms

HIPAA mark, CertReports state Vendor-statedSOC 2 mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedPCI DSS mark, CertReports state Vendor-statedISO 27001 mark, CertReports state Vendor-statedCSA STAR mark, CertReports state Verified
3 verified · 8 stated17 Sep 2026
Armis logo

Armis

Security

SOC 2 mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedISO 27001 mark, CertReports state Vendor-statedCSA STAR mark, CertReports state VerifiedCyber Essentials mark, CertReports state Vendor-statedISO 42001 mark, CertReports state Vendor-stated
3 verified · 10 stated17 Sep 2026
Drata logo

Drata

Compliance and GRC

HIPAA mark, CertReports state Vendor-statedSOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedISO 27001 mark, CertReports state Vendor-statedCSA STAR mark, CertReports state Verified
3 verified · 9 stated17 Sep 2026
Cyera logo

Cyera

Security

HIPAA mark, CertReports state Vendor-statedSOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedPCI DSS mark, CertReports state Vendor-statedISO 27001 mark, CertReports state Vendor-stated
3 verified · 8 stated17 Sep 2026
GitLab logo

GitLab

DevOps and observability

A complete DevOps platform delivered as a single application.

SOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedPCI DSS mark, CertReports state Vendor-statedISO 27001 mark, CertReports state Vendor-statedCSA STAR mark, CertReports state Verified
3 verified · 9 stated17 Sep 2026
OpenAI logo

OpenAI

AI infrastructure

SOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedPCI DSS mark, CertReports state Vendor-statedISO 27001 mark, CertReports state Vendor-statedCSA STAR mark, CertReports state Verified
2 verified · 11 stated17 Sep 2026
Wiz logo

Wiz

Security

HIPAA mark, CertReports state Vendor-statedSOC 2 mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedPCI DSS mark, CertReports state Vendor-statedISO 27001 mark, CertReports state Vendor-statedCSA STAR mark, CertReports state Verified
2 verified · 12 stated17 Sep 2026
Okta logo

Okta

Identity and access

HIPAA mark, CertReports state Vendor-statedSOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedPCI DSS mark, CertReports state Vendor-statedISO 27001 mark, CertReports state Vendor-stated
2 verified · 14 stated17 Sep 2026
Twilio logo

Twilio

Communications and CPaaS

HIPAA mark, CertReports state Vendor-statedSOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedPCI DSS mark, CertReports state VerifiedISO 27001 mark, CertReports state Vendor-statedISO 27017 mark, CertReports state Vendor-stated
2 verified · 7 stated17 Sep 2026
Fortinet logo

Fortinet

Security

HIPAA mark, CertReports state Vendor-statedSOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedISO 27001 mark, CertReports state Vendor-statedCSA STAR mark, CertReports state VerifiedISO 27017 mark, CertReports state Vendor-stated
2 verified · 10 stated17 Sep 2026
Diligent logo

Diligent

Compliance and GRC

HIPAA mark, CertReports state Vendor-statedSOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedISO 27001 mark, CertReports state Vendor-statedSOC 1 mark, CertReports state Vendor-stated
2 verified · 10 stated17 Sep 2026
A-LIGN logo

A-LIGN

Compliance and GRC

SOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedISO 27001 mark, CertReports state Vendor-statedISO 42001 mark, CertReports state Vendor-statedHITRUST mark, CertReports state Vendor-stated
2 verified · 5 stated17 Sep 2026
Ramp logo

Ramp

Finance and accounting

SOC 2 mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedPCI DSS mark, CertReports state VerifiedISO 27001 mark, CertReports state Vendor-statedSOC 1 mark, CertReports state Vendor-statedDPF mark, CertReports state Expired
2 verified · 7 stated17 Sep 2026
KnowBe4 logo

KnowBe4

Security

SOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedISO 27001 mark, CertReports state Vendor-statedCSA STAR mark, CertReports state VerifiedCyber Essentials mark, CertReports state Vendor-stated
2 verified · 10 stated17 Sep 2026
Axon logo

Axon

Government and public sector

HIPAA mark, CertReports state Vendor-statedSOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedFedRAMP mark, CertReports state VerifiedISO 27001 mark, CertReports state Vendor-statedCSA STAR mark, CertReports state Verified
2 verified · 15 stated17 Sep 2026
Intercom logo

Intercom

Customer support

HIPAA mark, CertReports state Vendor-statedSOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedISO 27001 mark, CertReports state Vendor-statedCSA STAR mark, CertReports state Vendor-statedISO 27701 mark, CertReports state Vendor-stated
1 verified · 10 stated17 Sep 2026
Zoom logo

Zoom

Video conferencing

SOC 2 mark, CertReports state Vendor-statedFedRAMP mark, CertReports state Vendor-statedPCI DSS mark, CertReports state Vendor-statedISO 27001 mark, CertReports state Vendor-statedCSA STAR mark, CertReports state Vendor-statedCyber Essentials mark, CertReports state Vendor-stated
1 verified · 18 stated17 Sep 2026
Vercel logo

Vercel

Cloud and hosting

HIPAA mark, CertReports state Vendor-statedSOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedPCI DSS mark, CertReports state Vendor-statedISO 27001 mark, CertReports state Vendor-statedSOC 3 mark, CertReports state Vendor-stated
1 verified · 8 stated17 Sep 2026
checkout logo

checkout

Payments

SOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedPCI DSS mark, CertReports state VerifiedISO 27001 mark, CertReports state Vendor-statedCyber Essentials mark, CertReports state Vendor-statedSOC 1 mark, CertReports state Vendor-stated
1 verified · 6 stated17 Sep 2026
Bird logo

Bird

Communications and CPaaS

The world’s largest omnichannel communications platform

HIPAA mark, CertReports state Vendor-statedSOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedISO 27001 mark, CertReports state Vendor-statedSOC 3 mark, CertReports state Vendor-statedDPF mark, CertReports state Verified
1 verified · 6 stated17 Sep 2026
Sim logo

Sim

AI infrastructure

The AI Workspace for Building and Managing AI Agents.

SOC 2 mark, CertReports state Vendor-statedGDPR mark, CertReports state Vendor-statedISO 27001 mark, CertReports state Vendor-statedDPF mark, CertReports state Verified
1 verified · 3 stated17 Sep 2026

Type I versus Type II

A Type I report describes controls at a point in time. A Type II report tests them over a period, commonly six to twelve months. Most buyers ask for Type II covering the last twelve months, or an older report with a bridge letter of at most three months.

Why nobody is "SOC 2 certified"

The AICPA issues no certificate and keeps no registry of audited organisations. A vendor that says "SOC 2 certified" usually means it has a report; CertReports records the report claim and flags the terminology.

How to get the report

SOC 2 reports are shared under NDA through the vendor trust centre. CertReports links to the request flow and never hosts, caches or summarises the report beyond facts the vendor has already published.