🎉 Phorion ranked #1 in independent EDR telemetry evaluations. Learn more

Phorion achieves SOC 2 Type II compliance

Phorion has achieved SOC 2 Type II compliance. The audit was conducted by independent auditor Insight Assurance, and the report is now available to customers and prospects through the Phorion Trust Portal.

What SOC 2 Type II covers

System and Organization Controls 2 (SOC 2) is an attestation framework developed by the American Institute of Certified Public Accountants (AICPA). It evaluates an organisation’s controls against the AICPA Trust Services Criteria, which cover areas such as security, availability, and confidentiality.

There are two types of SOC 2 report. A Type I report assesses whether controls are suitably designed at a single point in time. A Type II report goes further: the auditor tests both the design and the operating effectiveness of those controls over an observation period. The result shows how the controls work in practice, not just how they are documented.

Why it matters for an EDR vendor

Phorion builds endpoint detection and response (EDR) for macOS. Our agent runs with deep privileges on customer endpoints, and the telemetry it collects describes process activity, file access, and network behaviour across a fleet. That is sensitive data, and the access we hold is significant.

Customers are right to ask how we protect it. SOC 2 Type II answers that question with independent evidence covering how we secure our own infrastructure, how access to systems and data is managed, how changes are reviewed and deployed, and how customer data is handled. Security teams should expect this level of scrutiny from a security vendor, and we apply the same expectation to ourselves.

What this means for customers

In practical terms, the report makes vendor security reviews shorter. Rather than working through lengthy questionnaires from first principles, your security and procurement teams can rely on the auditor’s findings and focus their questions on what is specific to your environment.

The SOC 2 Type II report is available under a non-disclosure agreement (NDA) through our Trust Portal.

Thanks to Insight Assurance

We would like to thank the team at Insight Assurance for a thorough and well-run audit.

Ongoing work

Compliance is not a one-off exercise. Security and compliance are ongoing work at Phorion, and we will be audited annually to maintain our SOC 2 Type II attestation.

To request a copy of the report, visit trust.phorion.io. To see how Phorion protects macOS endpoints, get in touch to arrange a demo.

Let's Talk

See how Phorion protects your macOS fleet

Purpose-built by macOS security researchers. One lightweight agent delivering detection, prevention, and visibility.

Ready to see it in action? Book a demo and we'll show you how Phorion can protect your fleet.

Book a Demo

Error

Expect a personal email from our team.

Pricing About Us Blog