What This Means

Audited Controls You
Can Rely On

Nigama has successfully completed a SOC 2 Type II audit, performed by an independent, licensed CPA firm. This means our internal controls around security, availability, confidentiality, processing integrity, and privacy have been tested and verified to operate effectively over time — not just designed on paper.

This is the same standard trusted by leading SaaS and GRC companies worldwide, and it's the foundation VECTOR itself is built to help other companies achieve for their own compliance programs.

SOC 2 TYPE II AUDITED
Criteria Security
Access control & monitoring
Criteria Availability
Uptime & resilience
Criteria Confidentiality
Data protection commitments
Trust Services Criteria

The Five Principles
We're Audited Against

Security

Systems are protected against unauthorized access, both physical and logical.

Availability

Systems are available for operation and use as committed in our SLAs.

Confidentiality

Information designated as confidential is protected as committed or agreed.

Processing Integrity

System processing is complete, valid, accurate, timely, and authorized.

Privacy

Personal information is collected, used, retained, and disposed of in conformity with our commitments.

Common Questions

What is SOC 2 Type II?

SOC 2 Type II is an independent audit, performed by a third-party CPA firm, that evaluates whether a company's controls are not only well-designed but also operating effectively over a sustained observation period (rather than a single point in time, as with Type I).


What period does your audit cover?

Our SOC 2 Type II audit covers a 12-month observation window and is renewed annually to ensure continuous coverage.


Can I get a copy of the SOC 2 report?

Yes. Our full SOC 2 report is available to customers and prospects under a mutual NDA. Request a copy via our Contact page and our team will share it securely.


Does VECTOR help us with our own SOC 2 audit?

Yes — this is one of VECTOR's core use cases. VECTOR maps evidence you collect once to the SOC 2 Trust Services Criteria automatically, alongside any other frameworks you need to satisfy.

Request Our Report

Need Our SOC 2 Report
for a Vendor Review?

We share our full report with customers and prospects under NDA — reach out and we'll get it to you quickly.