An independent auditor has verified that our controls meet the AICPA Trust Services Criteria.
Last updated: July 4, 2026Nigama has successfully completed a SOC 2 Type II audit, performed by an independent, licensed CPA firm. This means our internal controls around security, availability, confidentiality, processing integrity, and privacy have been tested and verified to operate effectively over time — not just designed on paper.
This is the same standard trusted by leading SaaS and GRC companies worldwide, and it's the foundation VECTOR itself is built to help other companies achieve for their own compliance programs.
Systems are protected against unauthorized access, both physical and logical.
Systems are available for operation and use as committed in our SLAs.
Information designated as confidential is protected as committed or agreed.
System processing is complete, valid, accurate, timely, and authorized.
Personal information is collected, used, retained, and disposed of in conformity with our commitments.
SOC 2 Type II is an independent audit, performed by a third-party CPA firm, that evaluates whether a company's controls are not only well-designed but also operating effectively over a sustained observation period (rather than a single point in time, as with Type I).
Our SOC 2 Type II audit covers a 12-month observation window and is renewed annually to ensure continuous coverage.
Yes. Our full SOC 2 report is available to customers and prospects under a mutual NDA. Request a copy via our Contact page and our team will share it securely.
Yes — this is one of VECTOR's core use cases. VECTOR maps evidence you collect once to the SOC 2 Trust Services Criteria automatically, alongside any other frameworks you need to satisfy.