SOC 2 is an attestation framework from the AICPA. An independent auditor examines how a service organization handles five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.
Nekt holds a Type II report, the stronger of the two.
SOC 2 isn't legally required. We pursued it because companies that trust us with their data deserve evidence reviewed by someone who doesn't work for us. The annual audit is a forcing function that keeps our access controls, change management, and incident response disciplined year-round.
The audit was conducted by INTERCERT CPA LLC, an independent CPA firm. We use Scytale to monitor, collect, and submit evidence to auditors.
November 1, 2025 – February 28, 2026. Report issued May 25, 2026.
You can download a copy of the report here.
If you have a questionnaire that needs filling, please contact us.