← Security at Apptonomy
INDEPENDENT ASSURANCE
SOC 2 status and roadmap
A SOC 2 report is an independent auditor’s examination of a service organisation’s controls against the AICPA Trust Services Criteria. This page states where Apptonomy stands today, what already exists, and the order of the steps to an examination.
Last reviewed:
Where we stand
Apptonomy does not currently have a SOC 2 report, and no SOC 2 examination is currently underway.
The controls described on this page are our own practices. No independent auditor has examined them.
What exists today
- An internal gap analysis against all five Trust Services Criteria — security, availability, processing integrity, confidentiality and privacy — completed on 22 September 2026, with a remediation roadmap for its findings.
- An Information Security Policy and sixteen annexes, approved on 22 September 2026, each with an owner and an annual review date.
- Recurring controls with dated records, each first performed in September 2026: a control self-assessment, a quarterly access review, a backup restore test, an incident-response drill, an edge-rule review, and sanctions screening of our vendors.
- Automated checks that report when a policy passes its review date or a recurring control has no current dated record.
- Blocking dependency-vulnerability, secret and static-analysis scans on every code pull request, and monthly perimeter and cloud-configuration scans.
Roadmap
- Finish verifying environment isolation: staging now has its own customer database, identity and keys; the local, preview and sandbox paths still need the same proof.
- Commission an independent penetration test of the web application and API, planned for Q1 2027.
- Build operating history: run the recurring controls on their schedules and keep the dated records an auditor samples.
- Engage an independent auditor for a SOC 2 examination.
Security questions
Ask for the full answers, the evidence behind them, or anything this page does not cover.
security@apptonomy.ai