What is SOC 2?
SOC 2 Type II — Service Organization Control report evaluating security, availability, processing integrity, confidentiality, and privacy controls over a period of time.
Who needs SOC 2 depends on your industry, geography, and customers: buyers frequently require it from vendors during procurement, and compliance is typically demonstrated through independent audits, official registries, or formal certifications. Timeframes vary — most organizations plan months, not weeks, to prepare, be audited, and certify. For exact requirements, refer to the official SOC 2 program ↗.
Which tools in our directory have SOC 2?
1Password, Amazon Web Services, Amplitude, Apollo, Asana, Bill.com, Brex, ClickUp, Cloudflare, Confluence, CrowdStrike, Databricks, Datadog, dbt Labs, DigitalOcean, Figma, GitHub, Gong, Google Cloud Platform, HubSpot, Intercom, Jira, Linear, Looker, Microsoft Azure, Miro, Mixpanel, Monday.com, MongoDB Atlas, Netlify, Notion, Okta, Outreach, PagerDuty, Pipedrive, Ramp, Rippling, Salesforce, Segment, SendGrid, Slack, Snowflake, Snyk, Supabase, Tableau, Twilio, Vercel, Zendesk.
Additionally, 2 tools hold it partially or conditionally: Gusto, Deel (per-tool conditions apply — see their profiles).
Which tools don't have SOC 2?
.
"Not publicly documented" means we could not verify the status from public sources — it does not mean the vendor lacks the certification.