We’re pleased to announce that AwareGO has achieved SOC 2 Type 2 attestation, completing the milestone we set for ourselves when we announced our Type 1 report. An independent audit by Sensiba LLP has confirmed, with an unqualified opinion, that our security controls are not only suitably designed but operate effectively in practice.
What SOC 2 Type 2 means
SOC 2 is a widely recognized auditing framework developed by the AICPA. While a Type 1 report evaluates whether an organization’s controls are properly designed at a single point in time, a Type 2 report goes further. Independent auditors test the controls over an extended observation period to verify that they actually work, day in and day out.
For AwareGO, this examination covered the Trust Services Criteria for Security, Availability, and Confidentiality. The auditors tested our controls across areas including logical access management, encryption of customer data at rest and in transit, continuous vulnerability scanning, annual third-party penetration testing, incident response, disaster recovery, and change management. The result: no exceptions noted across all tested controls.
Why this matters for our customers and partners
Our customers and partners trust AwareGO with their training data and organizational insights. Many of them, from banks and healthcare providers to MSSPs serving hundreds of end clients, operate under strict regulatory and vendor-management requirements of their own. A SOC 2 Type 2 report gives their security and procurement teams independent, evidence-based assurance that our platform meets the standards they require, and it simplifies their own compliance and vendor review processes.
Achieving SOC 2 Type 2 closes the loop we opened with our Type 1 report. Anyone can describe good security controls on paper. What matters is proving they hold up in daily operations, under the scrutiny of independent auditors. That’s exactly what this attestation demonstrates, and it reflects how we’ve always believed security should be done: continuously, measurably, and transparently.
Ragnar Sigurdsson, CISSP / CEO and AwareGO co-founder
Security as an ongoing commitment
SOC 2 Type 2 is not a one-time achievement. The attestation covers a defined audit period and is renewed through recurring examinations, which means our controls remain under continuous independent scrutiny. Combined with our privacy-first approach, where features like Human Risk Insights deliver actionable analytics without processing personal data, this attestation reinforces AwareGO’s position as a trusted partner in human risk management.
Current and prospective customers can request a copy of the SOC 2 Type 2 report under NDA by contacting their AwareGO representative or reaching out through our website.