SOC 2 Type II
ActiveTrust services · auditor: Coalfire (independent)
Issued 2025-11-04
Expires 2026-11-03
Security · Availability · Confidentiality across production workloads, identity, treasury, and AI services.
Certifications & attestations
Every report below is held by an independent third party. We publish issue dates, expiry, scope, and a path to request the report under NDA — no “trust us” logos, no expired badges.
Active certifications
6
With named auditor
Jurisdictions covered
EU · UK · US
Plus DORA readiness
Reports renewable
Annual
Surveillance audits in between
Open findings
0 critical
2 informational, both in flight
Trust services · auditor: Coalfire (independent)
Issued 2025-11-04
Expires 2026-11-03
Security · Availability · Confidentiality across production workloads, identity, treasury, and AI services.
ISMS · auditor: BSI
Issued 2025-09-22
Expires 2028-09-21
Information Security Management System covering EU and US delivery; surveillance audits annual.
Cloud security · auditor: BSI
Issued 2025-09-22
Expires 2028-09-21
Cloud-specific controls for tenant isolation, shared-responsibility, and key management.
Cloud privacy · auditor: BSI
Issued 2025-09-22
Expires 2028-09-21
Protection of personally identifiable information in public cloud processing.
Payments · auditor: QSA (Foregenix)
Issued 2026-01-18
Expires 2027-01-17
Cardholder data environment scope: tokenised payments and treasury rails. No PAN storage.
Privacy · auditor: DPO + external counsel (Bird & Bird)
Issued 2026-02-04
Expires Continuous
Records of processing activities, ROPA, and lawful basis register; aligned with /legal/dpa.
EU resilience · auditor: KPMG advisory
Issued 2026-01-30
Expires Reviewed annually
ICT risk framework, incident reporting, digital operational resilience testing, third-party risk register.
Automotive supply · auditor: ENX-listed assessor
Issued Kickoff 2026-04
Expires Targeted 2026-Q4
Information security for automotive customers; assessment level AL3.
US health · auditor: Internal + legal
Issued 2025-12-12
Expires Reviewed annually
Mapping of safeguards to HIPAA Security Rule; ADmetric is not a covered entity but supports BAA on request.