Skip to main content
Redis logo

Redis

SOC 2 evidence

Redis is an in-memory key–value database, used as a distributed cache and message broker, with optional durability

redis.ioData platformsLast verified 19 Sep 2026
SOC 2 mark, CertReports state Vendor-stated as of 19 Sep 2026Vendor-stated

Redis and SOC 2

Redis states it holds a SOC 2 Type II report. CertReports captured this on 19 Sep 2026 from its trust centre (Drata); it is a vendor statement, not an independent confirmation.

Evidence

Vendor-statedVendor states SOC 2 Type 2 on its trust centre
as of 19 Sep 2026 · confidence 80%
Kind
type2
SourceCapturedQuoteLinks
Redis trust centre (Drata)
Vendor trust centre · HTTP 200
19 Sep 2026SOC 2 Type 2
Live page Snapshotsha256 aa710de333
Vendor-statedVendor states CSA STAR on its trust centre
as of 19 Sep 2026 · confidence 80%
SourceCapturedQuoteLinks
Redis trust centre (Drata)
Vendor trust centre · HTTP 200
19 Sep 2026CSA STAR
Live page Snapshotsha256 aa710de333

What is not public

  • The report period is not public, so CertReports cannot say whether the Redis SOC 2 report covers the last 12 months.
  • The audit firm is not stated in any public source CertReports has captured.
  • Trust services criteria in scope, carve-outs and bridge-letter status are only in the restricted-use report, which CertReports never hosts.
What SOC 2 means, and what it does not

SOC 2 reports are restricted-use and are never "certifications". A Type II report covers a period; freshness is the period end plus a bridge letter of at most three months. "SOC 2 ready" and "in progress" are not reports. No public SOC 2 registry exists; the strongest registry-grade signal is a CSA STAR Level 2 attestation, then a public SOC 3.

Read the SOC 2 guide and browse all vendors with evidence

Questions buyers ask

Is Redis SOC 2 certified?

No organisation is "SOC 2 certified": SOC 2 is an attestation report issued by a CPA firm, not a certification. Redis states it holds a SOC 2 Type II report as of 19 Sep 2026.

How do I get the Redis SOC 2 report?

SOC 2 reports are restricted-use documents shared under NDA. Request it through the Redis trust centre or security page; CertReports links to it and never hosts the report.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Change history

  1. 19 Sep 2026First indexed by CertReports12 evidence rows across 12 frameworks entered the index.

Alternatives with SOC 2 evidence

Similar vendors (shared product tags or the Data platforms category) whose SOC 2 row is verified or vendor-stated, ranked by similarity.