We are thrilled to share that Culture Amp has successfully received our SOC2 Type II report and attestation, further demonstrating our dedication to maintaining the highest standards of data security and privacy.
What is SOC2 Type II?
SOC2 Type II (System and Organization Controls) is an attestation an organization can obtain to show that there are good systems and processes in place to protect data and safeguard people’s privacy. The process of obtaining this involves an in-depth review by an independent party to make sure that the systems are designed well – and, more importantly – that they are operating in an effective manner.
Culture Amp is pleased to be able to share our achievement of this attestation and to assert our ongoing commitment to maintaining this certification.
Previous to receiving the SOC2 Type II, Culture Amp had SOC2 Type I. Here is how Type I and Type II attestation differs:
Type I focuses on the design effectiveness (are the procedures and processes written to a high standard) of data security and privacy processes, which are tested at a specific point in time (e.g., as of September 30, 2022).
Type II focuses on design and operating effectiveness to attest that processes for data security and privacy are both written to a high standard and followed consistently. This audit is done over a time period - usually six or 12-month increments.
What does this mean for our customers?
As an organization dedicated to putting people and customers first, it is obvious why the SOC2 Type II report is so important for Culture Amp. By attaining the SOC2 Type II attestation, we have successfully demonstrated the effectiveness of our security measures and internal controls over an extended period. This further demonstrates our commitment to providing our customers with a secure and reliable platform to manage employee feedback, engagement surveys, and other critical HR data.
We would like to express our gratitude for your continued trust and partnership. Achieving SOC2 Type II is a significant milestone for us, but it is only the beginning. We remain committed to investing in the security and privacy of your data and continually improving our processes so that you can stay focused on what matters most – building an intentional employee experience that engages your people and delivers results.
To learn more about Culture Amp’s commitment to data privacy and security, visit the Security Trust Center. To help facilitate your due diligence processes, you can also subscribe to be notified whenever updates are made.