Statsig
SOC 2 evidence
Statsig is your modern product development platform, with an integrated toolkit for experimentation, feature management, product analytics
Vendor-statedStatsig and SOC 2
Statsig states it holds a SOC 2 Type II report. CertReports captured this on 21 Sep 2026 from custom; it is a vendor statement, not an independent confirmation.
Evidence
- Kind
- type2
- Kind
- type2
What is not public
- The report period is not public, so CertReports cannot say whether the Statsig SOC 2 report covers the last 12 months.
- The audit firm is not stated in any public source CertReports has captured.
- Trust services criteria in scope, carve-outs and bridge-letter status are only in the restricted-use report, which CertReports never hosts.
What SOC 2 means, and what it does not
SOC 2 reports are restricted-use and are never "certifications". A Type II report covers a period; freshness is the period end plus a bridge letter of at most three months. "SOC 2 ready" and "in progress" are not reports. No public SOC 2 registry exists; the strongest registry-grade signal is a CSA STAR Level 2 attestation, then a public SOC 3.
Read the SOC 2 guide and browse all vendors with evidenceQuestions buyers ask
Is Statsig SOC 2 certified?
No organisation is "SOC 2 certified": SOC 2 is an attestation report issued by a CPA firm, not a certification. Statsig states it holds a SOC 2 Type II report as of 21 Sep 2026.
How do I get the Statsig SOC 2 report?
SOC 2 reports are restricted-use documents shared under NDA. Request it through the Statsig trust centre or security page; CertReports links to it and never hosts the report.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Change history
- 22 Sep 2026First indexed by CertReports7 evidence rows across 7 frameworks entered the index.
Alternatives with SOC 2 evidence
Similar vendors (shared product tags or the Developer tools category) whose SOC 2 row is verified or vendor-stated, ranked by similarity.
GrowthBook
Developer tools
Open source feature flagging and A/B testing
Split
Developer tools
Split.io feature flags connects critical impact data and alerts you whether your software changes are making things better or
Laravel
Developer tools
Laravel is a framework for building modern web apps and AI
Nango
Developer tools
A single API for all your integrations
Paragon
Developer tools
The embedded integration platform for SaaS apps.
Avo
Developer tools
Fixing data quality in product analytics.
Termius
Developer tools
Termius is an SSH client with team collaboration features
Buildkite
Developer tools
Buildkite is a continuous integration (CI) and continuous delivery (CD) platform used in DevOps
Understand SOC 2 evidence
All articlesSOC 2 Type I vs Type II: what each one proves to a buyer
Solomon Amos · 14 Sep 2026 · 10 min read