SOC 2
AICPA reviewed a full year of Shufti’s operational evidence
Shufti holds SOC 2 Type II certification, assessed by an AICPA-registered CPA firm over a continuous 12-month monitoring period. Type I shows controls exist on audit day. Type II shows they operated consistently over time. We hold Type II, covering all five Trust Services Criteria.
Certification Overview
What SOC 2 Covers
SOC 2 Type I, what we didn't stop at
Type I assesses whether the right security controls are in place at a single point in time. It confirms design, not execution. A vendor can pass Type I while running controls inconsistently in the months before or after the audit. It tells you what the vendor had on one particular day.
SOC 2 Type II, what Shufti holds
Type II assesses whether controls operated effectively throughout a 12-month monitoring period. Shufti auditor reviewed intrusion detection logs, access provisioning records for every role change, encryption key rotation schedules, change management approvals, incident response rehearsal documentation, and quarterly backup recovery test results. Certification came after that review.
Why It Matters
More than two-thirds of enterprise B2B buyers require SOC 2 Type II before executing vendor contracts. Without it, identity verification implementations stall in security review regardless of technical capability. The SOC 2 Type II report eliminates the need for custom security questionnaires, your InfoSec team reviews the actual audit evidence instead.
Shufti's Type II report is evidence that Shufti controls worked consistently
Across all five criteria, for a full year. Your team can review every control tested, every exception found, and every remediation taken, instead of sending us a 40-question questionnaire and hoping the answers are accurate.
2 months Continuous monitoring period
Assessed by an independent AICPA-registered auditor, not a point-in-time snapshot. All five Trust Services Criteria covered: Security, Availability, Processing Integrity, Confidentiality, Privacy.
Certification Assurance
Independently Verified Compliance Standards
Standard
All five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, Privacy.
Assessed By
Independent AICPA-registered CPA firm.
Scope
Full verification platform, including data ingestion, processing, storage, output, and sub-processors.
Documentation
Complete report available under signed NDA within one business day of request.
How Shufti Maintains It

Shufti current SOC 2 Type II report identifies the auditing firm, the 12-month monitoring period, the specific controls tested under each Trust Services Criterion, the evidence reviewed, and any exceptions, and how those exceptions were remediated. Subprocessors and their security obligations are disclosed in the report.

We maintain an active SOC 2 Type II report at all times. NDA-gated access typically takes one business day to arrange for enterprise clients and qualified prospects.




