Security & Compliance

SOC2 Type II Report.

Equabi maintains SOC2 Type II certification. Our controls are audited annually by an independent third-party assessor. The full report is available under NDA to customers and prospects.

SOC2 Type II

Audited annually

Encryption

AES-256 at rest, TLS 1.3

Access Controls

RBAC + MFA enforced

Pen Tested

Annual third-party

AICPA Trust Service Principles

Security

Protection of information and systems from unauthorized access, disclosure, and damage. Enforced via MFA, encrypted vaults, and network segmentation.

Availability

Information and systems are available for operation and use to meet objectives. 99.99% uptime SLA with multi-region failover.

Processing Integrity

System processing is complete, valid, accurate, and authorized. Every scan event is cryptographically signed and immutable.

Confidentiality

Information designated as confidential is protected per commitments. Vendor credentials never touch plaintext storage.

Privacy

Personal information is collected, used, retained, and disclosed in conformity with commitments. GDPR and CCPA compliant.

Audit Details

Auditor

Independent Third-Party Assessor

Framework

AICPA SOC2 / TSP 2017

Audit Period

January 1, 2026 – December 31, 2026

Report Type

Type II (Operational Effectiveness)

Next Audit

Q1 2027

Cloud Infrastructure

AWS (US-East-1, US-West-2)

Request the Full Report

The complete SOC2 Type II report is available under NDA. Enterprise customers can also request a DPA (Data Processing Agreement) and schedule a security review call with our engineering team.

© 2026 Equabi Inc. All rights reserved.