SOC 2 Type II, acrossall five trust criteria.

An independent examination of how Graphon protects the data you bring it. The report covers a three-month observation window, not a point in time, and it returned an unqualified opinion with no exceptions noted.

Opinion
Unqualified
Exceptions
None noted
Criteria
5 of 5
AICPA SOC 2 seal for service organizations
SOC 2 Type IIAICPA SOC for Service Organizations
SOC 2 compliant badge issued by Advantage Partners
Audited by Advantage PartnersIndependent examination, Seattle, WA

What was verified

Twenty-four of the controls the auditor tested over the three-month window, grouped by what they protect. Every one returned no exceptions.

Access4 controls

  • Production systems are remotely accessible only to authorised employees holding a valid MFA method.
  • Access reviews run at least quarterly across in-scope components, with required changes tracked to completion.
  • Authentication to the production network uses unique credentials or authorised SSH keys.
  • Access to migrate changes into production is restricted to authorised personnel.

Data4 controls

  • Customer data is encrypted both at rest and in transit.
  • Databases hold automated daily backups with point-in-time recovery; object storage uses versioning and multi-region replication.
  • Backups are encrypted at rest, and access to backup artefacts is restricted to named production personnel.
  • Data retention and disposal follow documented procedure.

Testing4 controls

  • An external security firm performs an annual penetration test of the production environment.
  • Automated vulnerability scans run quarterly against all external-facing systems.
  • Critical and high findings are tracked to remediation against defined SLAs.
  • Intrusion detection monitors for attacks originating outside the system boundary.

Response4 controls

  • A documented incident response plan governs security and privacy incidents.
  • Incidents are logged, tracked, resolved and communicated to affected parties.
  • A business continuity and disaster recovery plan is documented and tested at least annually.
  • A log management tool retains and monitors system activity.

People4 controls

  • Background checks are performed on new employees.
  • Confidentiality agreements are signed during onboarding.
  • Security awareness training is completed within 30 business days of hire.
  • Access is deactivated on an employee’s last working day, with evidence retained in the system audit log.

Vendors4 controls

  • Critical third-party vendors are reviewed at least annually.
  • Google Cloud’s own SOC 2 Type II and ISO 27001 reports are reviewed annually.
  • A configuration and change management process governs production changes.
  • Control self-assessments are performed at least annually.

All five criteria

A SOC 2 examination must cover Security. The other four are optional, and most reports leave them out. Ours covers every one.

  1. Security

    Systems are protected against unauthorised access, use and modification. The common criteria, required in every SOC 2 examination.

  2. Availability

    Systems are available for operation and use as committed and agreed.

  3. Processing integrity

    Processing is complete, valid, accurate, timely and authorised.

  4. Confidentiality

    Information designated as confidential is protected as committed and agreed.

  5. Privacy

    Personal information is collected, used, retained, disclosed and disposed of in line with our commitments.

Request the report

Talk to us about security

The full SOC 2 Type II report is available to customers and prospective customers under NDA. Send your company name and we will send the NDA, then the report.

hello@graphon.ai

Report dated August 28, 2026, issued by Advantage Partners. The AICPA licenses its SOC 2 seal for twelve months from that date, so this seal is current through August 28, 2027.

Bring a folder of video, images or documents. We will show you what Graphon finds in it, and where each answer came from.

SOC 2 Type II certifiedAll five trust services criteria · Read about security · Request the report