Graphwise Achieves SOC 2 Type II Compliance: Our Ongoing Commitment to Enterprise-Grade Security
Graphwise has officially achieved SOC 2 Type II compliance, an independently audited confirmation that its security controls are consistently effective over time, giving customers verified assurance around data protection, operational integrity, and enterprise-grade trust.
Main Takeaways
- Graphwise has officially achieved SOC 2 Type II compliance, independently verified by an AICPA-standard audit confirming its security controls are effective on an ongoing basis, not just on paper.
- Unlike SOC 2 Type I, which checks controls at a single point in time, Type II involves months of monitoring to prove consistent, day-to-day operational security.
- The audit covered access controls, change management, risk/incident response, and employee security training, giving customers verified assurance around data protection and compliance readiness.
- Graphwise frames this as a baseline rather than a finish line, committing to annual audits and continued investment as its platform and the threat landscape evolve.
At Graphwise, we have always believed that powerful data insights must be built on a foundation of absolute trust. As organizations increasingly rely on us to manage, analyze, and unlock the value of their interconnected data, safeguarding that information is our highest priority.
Today, we are proud to announce a major milestone in our security journey: Graphwise has officially achieved SOC 2 Type II compliance.
We have received our formal audit report, verifying that our internal security controls, systems, and processes meet the rigorous standards established by the American Institute of Certified Public Accountants (AICPA).
Here is a closer look at what this achievement means for Graphwise, our platform, and most importantly, our customers.
What is SOC 2 Type II compliance?
System and Organization Controls (SOC) 2 is a widely recognized auditing standard designed for technology and cloud-based service organizations. It evaluates an organization’s ability to protect customer data based on the Trust Services Criteria (TSC): Security, Availability, Processing Integrity, Confidentiality, and Privacy.
While a SOC 2 Type I report evaluates whether security controls are designed correctly at a single point in time, a SOC 2 Type II report is much more rigorous. It requires an independent, third-party auditor to monitor and test our controls over an extended period (typically several months) to prove that our security practices are consistently operational, effective, and reliable day in and day out.
Our successful Type II audit confirms that Graphwise doesn’t just have a strong security policy on paper — we live and breathe these practices every single day.
Why this matters to our customers
As enterprise data landscapes grow more complex, security cannot be an afterthought. Whether you are using Graphwise for advanced data analytics, knowledge graphs, or enterprise decision-making, you need to know your data is in safe hands.
Achieving SOC 2 Type II compliance offers our customers several key assurances:
- Validated Data Protection: Our audit verifies that we have robust defenses in place against unauthorized access, data breaches, and other vulnerabilities.
- Continuous Monitoring and Operational Integrity: Because Type II measures performance over time, you can trust that our systems are continuously monitored and that our team proactively manages risks.
- Streamlined Vendor Assessments: We know how time-consuming security reviews can be for your IT and procurement teams. Our SOC 2 Type II report provides immediate, standardized proof of our security posture, speeding up your internal approval processes.
- Alignment with Enterprise Standards: We are fully equipped to support enterprise clients with strict regulatory and compliance requirements.
What was evaluated in our audit?
Our independent audit thoroughly examined our entire operational environment, including:
- Access Controls: How we manage, authenticate, and restrict access to our production environments and customer data.
- Change Management: Our processes for safely developing, testing, and deploying updates to the Graphwise platform.
- Risk Management and Incident Response: Our readiness to detect, mitigate, and recover from potential security incidents or system disruptions.
- Employee Security Training: Ensuring every member of the Graphwise team is trained in modern security best practices and data privacy standards.
Looking ahead: security is a journey, not a destination
While we are incredibly proud of this achievement, we view SOC 2 Type II compliance as a baseline, not a finish line. Security is an ongoing commitment. As the threat landscape evolves and our platform grows, we will continue to invest in our infrastructure, refine our processes, and undergo annual audits to maintain the highest levels of trust.
We want to thank our engineering, security, and operations teams for their hard work in securing this milestone, and our customers for their continued trust in Graphwise.
Request Our SOC 2 Type II Report
Existing customers and prospective partners who wish to review a copy of our SOC 2 Type II report can request access by contacting their Graphwise account representative or by reaching out to our security team at security@graphwise.com.
(Note: Access to the report is provided under a standard Non-Disclosure Agreement).
FAQ
Any Questions? Look Here
The primary difference between SOC 2 Type I and Type II compliance lies in the timeframe and the depth of the evaluation: a Type I report assesses the design and implementation of security controls at a single point in time, verifying that they are structured correctly to meet trust criteria, whereas a Type II report evaluates the operating effectiveness of those same controls over a sustained period, typically ranging from three to twelve months. While Type I provides a quick snapshot of an organization's security posture, Type II is considered more rigorous and provides greater assurance to customers because it proves that the security measures are not just theoretically sound but are also being consistently and effectively maintained in practice.
SOC 2 and ISO 27001 are both voluntary security frameworks aimed at protecting data, but they differ significantly in scope, methodology, and regional preference. ISO 27001 is a globally recognized standard that focuses on establishing and maintaining a comprehensive Information Security Management System (ISMS) across an entire organization, resulting in a formal certification valid for three years. In contrast, SOC 2 is primarily prevalent in North America and serves as an attestation report issued by a CPA firm to verify that specific security controls meet selected Trust Services Criteria (such as security, availability, or privacy). While ISO 27001 is more prescriptive regarding the organizational management system, SOC 2 offers greater flexibility for service providers to customize controls based on their specific product or client needs.
Enterprises require SOC 2 reports as a critical component of their vendor risk management process to obtain independent, third-party verification that a software provider maintains robust security, availability, and privacy controls. Because enterprises often outsource core business functions to SaaS providers, they must ensure that these vendors can protect sensitive data and comply with overarching regulatory frameworks like GDPR or HIPAA. A SOC 2 Type 2 report, in particular, provides a reliable audit trail demonstrating that security protocols were consistently followed over time, rather than just at a single point. This validation allows procurement and security teams to mitigate potential liabilities, bypass the manual burden of exhaustive security questionnaires, and establish the trust necessary for a long-term business relationship.