Yes. Pangram has completed a SOC 2 Type II audit and maintains SOC 2 Type II compliance on an ongoing basis.
What that means in practice
Independently audited: Our security program is audited against the SOC 2 Type II standard by the AICPA. Type II means the audit evaluates how our controls operate over a period of time, not just at a single point.
Built on recognized frameworks: Our controls are built on NIST 800-53r5 and ISO 27017 standards and are continuously evaluated as part of our SOC 2 Type II audit.
Continuous monitoring: We use automated compliance monitoring to keep controls in effect between audits, so compliance is maintained on an ongoing basis rather than only at audit time.
Getting a copy of our report
Our SOC 2 Type II report is available to customers and prospects on request, typically under an NDA. Reach out to your Pangram contact or email us at support@pangram.com to receive a copy.
Questions?
For security or compliance questions, contact support@pangram.com. Our full privacy policy is available at https://www.pangram.com/privacy-policy.html.
