SOC 2

Nekt is SOC 2 Type II compliant. Our security controls are audited by an independent CPA firm on a recurring basis.

What is SOC 2?

SOC 2 is an attestation framework from the AICPA. An independent auditor examines how a service organization handles five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.

  • Type I checks whether controls are designed appropriately at a point in time.
  • Type II verifies those controls actually operated effectively across an observation window. Auditors pull samples and confirm the policy was followed.

Nekt holds a Type II report, the stronger of the two.

Why it matters

SOC 2 isn't legally required. We pursued it because companies that trust us with their data deserve evidence reviewed by someone who doesn't work for us. The annual audit is a forcing function that keeps our access controls, change management, and incident response disciplined year-round.

Who audited us?

The audit was conducted by INTERCERT CPA LLC, an independent CPA firm. We use Scytale to monitor, collect, and submit evidence to auditors.

Audit period

November 1, 2025 – February 28, 2026. Report issued May 25, 2026.

How can I access the SOC 2 report?

You can download a copy of the report here.

Can you answer a questionnaire?

If you have a questionnaire that needs filling, please contact us.