Phorion has achieved SOC 2 Type II compliance. The audit was conducted by independent auditor Insight Assurance, and the report is now available to customers and prospects through the Phorion Trust Portal.
What SOC 2 Type II covers
System and Organization Controls 2 (SOC 2) is an attestation framework developed by the American Institute of Certified Public Accountants (AICPA). It evaluates an organisation’s controls against the AICPA Trust Services Criteria, which cover areas such as security, availability, and confidentiality.
There are two types of SOC 2 report. A Type I report assesses whether controls are suitably designed at a single point in time. A Type II report goes further: the auditor tests both the design and the operating effectiveness of those controls over an observation period. The result shows how the controls work in practice, not just how they are documented.
Why it matters for an EDR vendor
Phorion builds endpoint detection and response (EDR) for macOS. Our agent runs with deep privileges on customer endpoints, and the telemetry it collects describes process activity, file access, and network behaviour across a fleet. That is sensitive data, and the access we hold is significant.
Customers are right to ask how we protect it. SOC 2 Type II answers that question with independent evidence covering how we secure our own infrastructure, how access to systems and data is managed, how changes are reviewed and deployed, and how customer data is handled. Security teams should expect this level of scrutiny from a security vendor, and we apply the same expectation to ourselves.
What this means for customers
In practical terms, the report makes vendor security reviews shorter. Rather than working through lengthy questionnaires from first principles, your security and procurement teams can rely on the auditor’s findings and focus their questions on what is specific to your environment.
The SOC 2 Type II report is available under a non-disclosure agreement (NDA) through our Trust Portal.
Thanks to Insight Assurance
We would like to thank the team at Insight Assurance for a thorough and well-run audit.
Ongoing work
Compliance is not a one-off exercise. Security and compliance are ongoing work at Phorion, and we will be audited annually to maintain our SOC 2 Type II attestation.
To request a copy of the report, visit trust.phorion.io. To see how Phorion protects macOS endpoints, get in touch to arrange a demo.
